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ABSTRACT 

We present a new role system for specifying changing refer- 
encing relationships of heap objects. The role of an object 
depends, in large part, on its aliasing relationships with other 
objects, with the role of each object changing as its aliasing 
relationships change. Roles therefore capture important ob- 
ject and data structure properties and provide useful infor- 
mation about how the actions of the program interact with 
these properties. Our role system enables the programmer 
to specify the legal aliasing relationships that define the set 
of roles that objects may play, the roles of procedure param- 
eters and object fields, and the role changes that procedures 
perform while manipulating objects. We present an inter- 
procedural, compositional, and context-sensitive role analy- 
sis algorithm that verifies that a program respects the role 
constraints. 
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1 Introduction 

Types capture important properties of the objects that pro- 
grams manipulate, increasing both the safety and readability 
of the program. Traditional type systems capture properties 
(such as the format of data items stored in the fields of the 
object) that are invariant over the lifetime of the object. But 
in many cases, properties that do change are as important 



as properties that do not. Recognizing the benefit of cap- 
turing these changes, researchers have developed systems in 
which the type of the object changes as the values stored in 
its fields change or as the program invokes operations on the 
object [44, 43, 10, 47, 48, 4, 20, 13]. These systems integrate 
the concept of changing object states into the type system. 

The fundamental idea in this paper is that the state of 
each object also depends on the data structures in which it 
participates. Our type system therefore captures the refer- 
encing relationships that determine this data structure par- 
ticipation. As objects move between data structures, their 
types change to reflect their changing relationships with 
other objects. Our system uses roles to formalize the con- 
cept of a type that depends on the referencing relationships. 
Each role declaration provides complete aliasing information 
for each object that plays that role — in addition to specify- 
ing roles for the fields of the object, the role declaration also 
identifies the complete set of references in the heap that refer 
to the object. In this way roles generalize linear type sys- 
tems [45, 2, 30] by allowing multiple aliases to be statically 
tracked, and extend alias types [42, 46] with the ability to 
specify roles of objects that are the source of aliases. 

This approach attacks a key difficulty associated with 
state-based type systems: the need to ensure that any state 
change performed using one alias is correctly reflected in the 
declared types of the other aliases. Because each object's 
role identifies all of its heap aliases, the analysis can verify 
the correctness of the role information at all remaining or 
new heap aliases after an operation changes the referencing 
relationships. 

Roles capture important object and data structure prop- 
erties, improving both the safety and transparency of the 
program. For example, roles allow the programmer to ex- 
press data structure consistency properties (with the proper- 
ties verified by the role analysis), to improve the precision of 
procedure interface specifications (by allowing the program- 
mer to specify the role of each parameter), to express precise 
referencing and interaction behaviors between objects (by 
specifying verified roles for object fields and aliases), and to 
express constraints on the coordinated movements of objects 
between data structures (by using the aliasing information in 
role definitions to identify legal data structure membership 
combinations). Roles may also aid program optimization by 
providing precise aliasing information. 

This paper makes the following contributions: 

• Role Concept: The concept that the state of an ob- 
ject depends on its referencing relationships; specifi- 
cally, that objects with different heap aliases should be 
regarded as having different states. 

• Role Definition Language: It presents a language 
for defining roles. The programmer can use this lan- 
guage to express data structure invariants and proper- 
ties such as data structure participation. 

• Programming Model: It presents a set of role con- 
sistency rules. These rules give a programming model 
for changing the role of an object and the circumstances 
under which roles can be temporarily violated. 

• Procedure Interface Specification Language: It 

presents a language for specifying the initial context 
and effects of each procedure. The effects summarize 
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Figure 1: Role Reference Diagram for Scheduler 



the actions of the procedure in terms of the references 
it changes and the regions of the heap that it affects. 

• Role Analysis Algorithm: It presents an algorithm 
for verifying that the program respects the constraints 
given by a set of role definitions and procedure spec- 
ifications. The algorithm uses a data-flow analysis to 
infer intermediate referencing relationships between ob- 
jects, allowing the programmer to focus on role changes 
and procedure interfaces. 

2 Example 

Figure 1 presents a role reference diagram for a process 
scheduler. Each box in the diagram denotes a disjoint set of 
objects of a given role. The labelled arrows between boxes 
indicate possible references between the objects in each set. 
As the diagram indicates, the scheduler maintains a list of 
live processes. A live process can be either running or sleep- 
ing. The running processes form a doubly-linked list, while 
sleeping processes form a binary tree. Both kinds of pro- 
cesses have proc references from the live list nodes LiveList. 
Header objects RunningHeader and SleepingTree simplify 
operations on the data structures that store the process ob- 
jects. 

As Figure 1 shows, data structure participation deter- 
mines the conceptual state of each object. In our exam- 
ple, processes that participate in the sleeping process tree 
data structure are classified as sleeping processes, while pro- 
cesses that participate in the running process list data struc- 
ture are classified as running processes. Moreover, move- 
ments between data structures correspond to conceptual 
state changes — when a process stops sleeping and starts run- 
ning, it moves from the sleeping process tree to the running 
process list. 

2.1 Role Definitions 

Figure 2 presents the role definitions for the objects in our 
example. 1 Each role definition specifies the constraints that 
an object must satisfy to play the role. Field constraints 

'in general, each role definition would specify the static 
class of objects that can play that role. To simplify the 



specify the roles of the objects to which the fields refer, while 
slot constraints identify the number and kind of aliases of the 
object. 

role LiveHeader { 

fields next : LiveList | null; 
} 
role LiveList { 

fields next : LiveList | null, 

proc : RunningProc | SleepingProc; 
slots LiveList .next | LiveHeader .next ; 
acyclic next; 
} 
role RunningHeader { 

fields next : RunningProc | RunningHeader, 
prev : RunningProc | RunningHeader; 
slots RunningHeader. next | RunningProc. next , 
RunningHeader. prev | RunningProc. prev; 
identities next. prev, prev. next; 
} 
role RunningProc { 

fields next : RunningProc | RunningHeader, 
prev : RunningProc | RunningHeader; 
slots RunningHeader. next | RunningProc. next , 
RunningHeader. prev | RunningProc. prev, 
LiveList .proc; 
identities next. prev, prev. next; 
} 
role SleepingTree { 

fields root : SleepingProc | null, 
acyclic left, right; 
} 
role SleepingProc { 

fields left : SleepingProc | null, 
right : SleepingProc | null; 
slots SleepingProc. left | SleepingProc. right | 
SleepingTree . root ; 
LiveList .proc; 
acyclic left, right; 
} 
role DeadProc { } 



Figure 2: Role Definitions for a Scheduler 

Role definitions may also contain two additional kinds of 
constraints: identity constraints, which specify paths that 
lead back to the object, and acyclicity constraints, which 
specify paths with no cycles. In our example, the identity 
constraint next. prev in the RunningProc role specifies the 
cyclic doubly-linked list constraint that following the next, 
then prev fields always leads back to the initial object. The 
acyclic constraint left, right in the SleepingProc role 
specifies that there are no cycles in the heap involving only 
left and right edges. On the other hand, the list of run- 
ning processes must be cyclic because its nodes can never 
point to null. 

The slot constraints specify the complete set of heap 
aliases for the object. In our example, this implies that no 
process can be simultaneously running and sleeping. 

presentation, we assume that all objects are instances of a 
single class with a set of fields F. 



In general, roles can capture data structure consistency 
properties such as disjointness and can prevent representa- 
tion exposure [8]. As a data structure description language, 
roles can naturally specify trees with additional pointers. 
Roles can also approximate non-tree data structures like 
sparse matrices. Because most role constraints are local, 
it is possible to inductively infer them from data structure 
instances. 

2.2 Roles and Procedure Interfaces 

Procedures specify the initial and final roles of their parame- 
ters. The suspend procedure in Figure 3, for example, takes 
two parameters: an object with role RunningProc p, and 
the SleepingTree s. The procedure changes the role of the 
object referenced by p to SleepingProc whereas the object 
referenced by s retains its original role. To perform the role 
change, the procedure removes p from its RunningList data 
structure and inserts it into the SleepingTree data struc- 
ture s. If the procedure fails to perform the insertions or 
deletions correctly, for instance by leaving an object in both 
structures, the role analysis will report an error. 

procedure suspend (p : RunningProc -» SleepingProc, 

s : SleepingTree) 
local pp, pn, r; 
{ 

pp = p . prev ; pn = p . next ; 

r = s.root; 

p . prev = null ; p . next = null ; 

pp. next = pn; pn.prev = pp; 

s.root = p; p. left = r; 

setRole(p : SleepingProc); 
} 



Figure 3: Suspend Procedure 



3 Abstract Syntax and Semantics of Roles 

In this section, we precisely define what it means for a given 
heap to satisfy a set of role definitions. In subsequent sec- 
tions we will use this definition as a starting point for a 
programming model and role analysis. 



3.1 Heap Representation 

We represent a concrete program heap as a finite directed 
graph H c with nodes(if c ) representing objects of the heap 
and labelled edges representing heap references. A graph 
edge {oi,/, 02} G H c denotes a reference with field name / 
from object 01 to object 02. To simplify the presentation, we 
fix a global set of fields F and assume that all objects have 
all fields in F. We do not consider subtyping or dynamic 
dispatch in this paper. 

3.2 Role Representation 

Let R denote the set of roles used in role definitions, nulln be 
a special symbol always denoting a null object null c , and let 



Ro = -RUJnullij}. We represent each role as the conjunction 
of the following four kinds of constraints: 

• Fields: For every field name / G F we introduce a 
function field/ : R — > 2 R ° denoting the set of roles 
that objects of role r G R can reference through field 
/. A field / of role r can be null if and only if 
nullij G field/(r). The explicit use of nulljj and the pos- 
sibility to specify a set of alternative roles for every field 
allows roles to express both may and must referencing 
relationships. 

• Slots: Every role r has slotno(r) slots. A slot slotk(r) of 
role r G R is a subset of R x F. Let o be an object of role 
r and o' an object of role r'. A reference (o', /, o) G H c 
can fill a slot k of object o if and only if {r 1 , /) G slot*; (r ) . 
An object with role r must have each of its slots filled 
by exactly one reference. 

• Identities: Every role r G R has a set of identities(r) C 
F x F. Identities are pairs of fields {/, g) such that 
following reference / on object o and then returning on 
reference g leads back to o. 

• Acyclicities: Every role r G R has a set acyclic(r) C F 
of fields along which cycles are forbidden. 

3.3 Role Semantics 

We define the semantics of roles as a conjunction of invari- 
ants associated with role definitions. A concrete role assign- 
ment is a map p c : nodes(.ff c ) — > Ro such that p c ( n u I l c ) = 
nullij. 

Definition 1 Given a set of role definitions, we say that 
heap H c is role consistent iff there exists a role assignment 
p c : nodes(.ff c ) — > Ro such that for every o G nodes(i? c ) the 
predicate locallyConsistent(o, H c ,p c ) is satisfied. We call any 
such role assignment p c a valid role assignment. 

The predicate locallyConsistent(o, H c ,p c ) formalizes the con- 
straints associated with role definitions. 

Definition 2 locallyConsistent(o, H c ,p c ) iff all of the fol- 
lowing conditions are met. Let r = p c (o). 

1) For every field f G F and {o,f,o'} G H c , p c {o') G 
field/(r). 

2) Let {{o u /!),... >*,/*)} = {{o'J) | {o',f,o) G 
H c } be the set of all aliases of node o. Then k = 
slotno(r) and there exists some permutation p of the 
set {1, . . . ,k} such that (p c (oi), fi) G slot Pi (r) for all i. 

3) If(o,f,cf) G H c , (d,g,o") G H c , and 
{/,<?) G identities(r), then o = o" . 

4) It is not the case that graph H c contains a cycle 
o\ , f\ , . . . , o s , f s , o\ where o\ = o and 

fi,... ,f s G acyclic(r) 

Note that a role consistent heap may have multiple valid 
role assignments p c . However, in each of these role assign- 
ments, every object o is assigned exactly one role p c {o). 
The existence of a role assignment p c with the property 
pc(oi) ^ pc{o2) thus implies o\ =£ 02. This is just one of 
the ways in which roles make aliasing more predictable. 



4 Role Properties 

Roles capture important properties of the objects and pro- 
vide useful information about how the actions of the program 
affect those properties. 

• Consistency Properties: Roles can ensure that the 
program respects application-level data structure con- 
sistency properties. The roles in our process scheduler, 
for example, ensure that a process cannot be simultar 
neously sleeping and running. 

• Interface Changes: In many cases, the interface of an 
object changes as its referencing relationships change. 
In our process scheduler, for example, only running pro- 
cesses can be suspended. Because procedures declare 
the roles of their parameters, the role system can en- 
sure that the program uses objects correctly even as the 
object's interface changes. 

• Multiple Uses: Code factoring minimizes code dupli- 
cation by producing general-purpose classes (such as 
the Java Vector and Hashtable classes) that can be 
used in a variety of contexts. But this practice ob- 
scures the different purposes that different instances of 
these classes serve in the computation. Because each in- 
stance's purpose is usually reflected in its relationships 
with other objects, roles can often recapture these dis- 
tinctions. 

• Correlated Relationships: In many cases, groups 
of objects cooperate to implement a piece of function- 
ality. Standard type declarations provide some infor- 
mation about these collaborations by identifying the 
points-to relationships between related objects at the 
granularity of classes. But roles can capture a much 
more precise notion of cooperation, because they track 
correlated state changes of related objects. 

Programmers can use roles for specifying the membership 
of objects in data structures and the structural invariants 
of data structures. In both cases, the slot constraints are 
essential. 

When used to describe membership of an object in a data 
structure, slots specify the source of the alias from a data 
structure node that stores the object. By assigning different 
sets of roles to data structures used at different program 
points, it is possible to distinguish nodes stored in different 
data structure instances. As an object moves between data 
structures, the role of the object changes appropriately to 
reflect the new source of the alias. 

When describing nodes of data structures, slot constraints 
specify the aliasing constraints of nodes; this is enough to 
precisely describe a variety of data structures and approxi- 
mate many others. Property 16 below shows how to identify 
trees in role definitions even if tree nodes have additional 
aliases from other sets of nodes. It is also possible to define 
nodes which make up a compound data structure linked via 
disjoint sets of fields, such as threaded trees, sparse matrices 
and skip lists. 

Example 3 The following role definitions specify a sparse 
matrix of width and height at least 3. These definitions can 
be easily constructed from a sketch of a sparse matrix, as in 
Figure 4. 





Figure 4: Roles of Nodes of a Sparse Matrix 



role Al { 

fields right : A2, down : A4; 

acyclic right, down; 
} 
role A2 { 

fields right : A2 | A3, down : A5; 

slots Al. right | A2. right; 

acyclic right, down; 
} 
role A3 { 

fields down : A6; 

slots A2. right; 

acyclic right, down; 
} 
role A4 { 

fields right : A5, down : A4 | A7; 

slots Al.down | A4.down; 

acyclic right, down; 
} 
role A5 { 

fields right : A5 I A6, down : A5 I A8; 

slots A4. right | A5. right, A2.down | A5.down; 

acyclic right, down; 
} 
role A6 { 

fields down : A6 I A9; 

slots A5. right, A3. down | A6.down; 

acyclic right, down; 
} 
role A7 { 

fields right : A8; 

slots A4.down; 

acyclic right, down; 
} 
role A8 { 

fields right : A8 I A9; 

slots A7. right | A8. right, A5.down; 

acyclic right, down; 
} 
role A9 { 

slots A8. right, A6.down; 

acyclic right, down; 
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Figure 5: Sketch of a Two-Level Skip List 



Example 4 We next give role definitions for a two-level 
skip list [36] sketched in Figure 5. 

role SkipList { 

fields one : OneNode | TwoNode | null; 
two : TwoNode | null ; 
} 
role OneNode { 

fields one : OneNode | TwoNode | null; 

two : null; 
slots OneNode. one | TwoNode. one | SkipList . one; 
acyclic one, two; 
} 
role TwoNode { 

fields one : OneNode | TwoNode | null; 

two : TwoNode | null ; 
slots OneNode. one | TwoNode. one | SkipList . one, 

TwoNode. two | SkipList .two; 
acyclic one, two; 
} 

4.1 Formal Properties of Roles 

In this section we identify some of the invariants expressible 
using sets of mutually recursive role definitions. A further 
study of role properties can be found in [31]. 

The following properties show some of the ways role spec- 
ifications make object aliasing more predictable. They are 
an immediate consequence of the semantics of roles. 



Property 5 (Rol 

If there exists a valid role assignment p c for H c such that 

p(oi) / p(o 2 ), then oi =fc o 2 . 

The previous property gives a simple criterion for showing 
that objects o\ and 02 are unaliased: find a valid role as- 
signment which assigns different roles to o\ and oi- This 
use of roles generalizes the use of static types for pointer 
analysis [12]. Since roles create a finer partition of objects 
than a typical static type system, their potential for proving 
absence of aliasing is even larger. 

Property 6 (Disjointness Propagation) 
If{o\, f, 02), (03,5,04) G H c , o\ ^=03, and there exists a valid 
role assignment p c for H c such that p c {o2) = pcipn) = r but 
field/ (r) fl field 9 (r) = 0, then 02 ^04. 

Property 7 (Generalized Uniqueness) 

If (01, /, 02), (03, 5,04) G H c , o\ =£ 03, and there exists a 
role assignment p c such that p c {o2) = pc{oi) = r, but there 
are no indices i =/= j such that (/9c(oi),/) G slot,(r) and 
(pc(o2), (?) G slotj(r) then 02 / 04. 



A special case of Property 7 occurs when slotno(r) = 1; this 
constrains all references to objects of role r to be unique. 

Role definitions induce a role reference diagram RRD 
which captures some, but not all, role constraints. 

Definition 8 (Role Reference Diagram) 
Given a set of definitions of roles R, a role reference diagram 
RRD is is a directed graph with nodes Ro and labelled edges 
defined by 

RRD = {{r,/,r') | r' G field/ (r) and Si {r, /) G slotj(r')} 
U {<r, /, nullij) | null* G field/ (r)} 

Each role reference diagram is a refinement of the corre- 
sponding class diagram in a statically typed language, be- 
cause it partitions classes into multiple roles according to 
their referencing relationships. The sets /5^" 1 (r) of objects 
with role r change during program execution, reflecting the 
changing referencing relationships of objects. 

Role definitions give more information than a role refer- 
ence diagram. Slot constraints specify not only that objects 
of role ri can reference objects of role r 2 along field /, but 
also give cardinalities on the number of references from other 
objects. In addition, role definitions include identity and 
acyclicity constraints, which are not present in role refer- 
ence diagrams. 

Property 9 Let p c be any valid role assignment. Define 

G = {(p c (o 1 )J,p c (o2))\{o 1 ,f,o 2 )eH c } 
Then G is a subgraph of RRD. 

It follows from Property 9 that roles give an approximation 
of may-reachability among heap objects. 

Property 10 (May Reachability) 

If there is a valid role assignment p c ■ nodes(-ff c ) — ► Ro such 
that pc(oi) =£ pc{o2) where 01,02 G nodes(-ffc) and there is 
no path from p c (oi) to p c (o2) in the role reference diagram 
RRD, then there is no path from o\ to 02 in H c . 

The next property shows the advantage of explicitly speci- 
fying null references in role definitions. While the ability to 
specify acyclicity is provided by the acyclic constraint, it 
is also possible to indirectly specify must-cyclicity. 

Property 11 (Must Cyclicity) 

Let Fo C F and Rcyc C. R be a set of nodes in the role ref- 
erence diagram RRD such that for every node r G Rcyc, if 
{r,f,r') G RRD then r' G Rcyc- If pc is a valid role assign- 
ment for H c , then every object o\ G H c with p c {o\) G Rcyc 
is a member of a cycle in H c with edges from Fo . 

The following property shows that roles can specify a form 
of must-reachability among the sets of objects with the same 
role. 

Property 12 (Downstream Path Termination) 
Assume that for some set of fields ftCF there are sets of 
nodes Rinter Cj R, Rfinal C Ro of the role reference diagram 
RRD such that for every node r G -Rinter-' 

1. F C acyclic(r) 

2. if (r, f,r') G RRD for f G F , then r' G Rinter U Rfinal 



Let p c be a valid role assignment for H c . Then every path in 
H c starting from an object 01 with role p c {oi) G Rinter and 
containing only edges labelled with Fo is a prefix of a path 
that terminates at some object 02 with p c (o2) G -Rfinal- 

Property 13 (Upstream Path Termination) 
Assume that for some set of fields ftCF there are sets of 
nodes Rinter C R, R mj C _R of the role reference diagram 
RRD such that for every node r G -Rinter-' 

1. Fo C acyclic(r) 

2. if (r'J, r) G RRD for f G F , then r' G Rinter U Rinit 

Let p c be a valid role assignment for H c . Then every path 
in H c terminating at an object 02 with p c (o2) G -Rinter and 
containing only edges labelled with Fo is a suffix of a path 
which started at some object o\, where p c (oi) G Rinit- 

The next two properties guarantee reachability properties 
by which there must exist at least one path in the heap, 
rather than stating properties of all paths as in Properties 
12 and 13. 

Property 14 (Downstream Must Reachability) 
Assume that for some set of fields ft^f there are sets of 
roles -Rinter C R, -Rfinal C Ro of the role reference diagram 
RRD such that for every node r G Rinter-' 

1. Fo C acyclic(r) 

2. there exists f G Fo such that field/ (r) C Rinter U Rfinal 

Let p c be a valid role assignment for H c . Then for every 
object 01 with p c {oi) G Rinter there is a path in H c with edges 
from Fo from Oi to some object 02 where p c {p2) G Rfinal- 

Property 15 (Upstream Must Reachability) 
Assume that for some set of fields Fo C F there are sets 
of nodes -Rinter C R, R mn C R of the role reference diagram 
RRD such that for every node r G -Rinter-' 

1. Fo C acyclic(r) 

2. there exists k such that slotfc(r) C (Rinter U Rinit) x F 

Let p c be a valid role assignment for H c . Then for every 
object 02 with p c (o2) G -Rinter there is a path in H c from 
some object Oi with p c (oi) G Rinit to the object o 2 - 

Trees are a class of data structures especially suited for 
static analysis. Roles can express graphs that are not trees, 
but it is useful to identify trees as certain sets of mutually 
recursive role definitions. 

Property 16 (Treeness) 

Let -Rtree Cj R be a set of roles and ftCF set of fields such 
that for every r G -Rtree 

1. F C acyclic(r) 

2. \{i I sloti(r) n (Rtree x F ) + 0}| < 1 

Let pc be a valid role assignment for H c and S C 
{{m,/,n 2 ) I (ni,/,n 2 ) G H c ,p(ni),p(ri2) G Rtree,/ G F }. 
Then S is a set of trees. 



5 A Programming Model 

In this section we define what it means for an execution of 
a program to respect the role constraints. This definition 
is complicated by the need to allow the program to tem- 
porarily violate the role constraints during data structure 
manipulations. Our approach is to let the program violate 
the constraints for objects referenced by local variables or 
parameters, but require all other objects to satisfy the con- 
straints. 

We first present a simple imperative language with dy- 
namic object allocation and give its operational semantics. 
We then specify additional statement preconditions that en- 
force the role consistency requirements. 

5.1 A Simple Imperative Language 

Our core language contains, as basic statements, Load 
(x=y.f), Store (x.f=y), Copy (x=y), and New (x=new). All 
variables are references to objects in the global heap and all 
assignments are reference assignments. We use an elemen- 
tary test statement combined with nondeterministic choice 
and iteration to express if and while statement, using the 
usual translation [22, 1]. We represent the control flow of 
programs using control-flow graphs. 

A program is a collection of procedures proc G Proc. Pro- 
cedures change the global heap but do not return values. 
Every procedure proc has a list of parameters param(proc) = 
{parang (proc)}, and a list of local variables local(proc). We 
use var(proc) to denote param(proc) U local(proc). A proce- 
dure definition specifies the initial role preRj.(proc) and the 
final role postR A .(proc) for every parameter param A .(proc). We 
use proCj for indices j G N to denote activation records of 
procedure proc. We further assume that there are no modifi- 
cations of parameter variables so every parameter references 
the same object throughout the lifetime of procedure acti- 
vation. 

Example 17 The following kill procedure removes a pro- 
cess from both the doubly linked list of running processes 
and the list of all active processes. This is indicated by the 
transition from RunningProc to DeadProc. 

procedure kill(p : RunningProc -» DeadProc, 

1 : LiveHeader) 
local prev, current, cp, nxt, lp, In; 
{ 

// find 'p' in '1' 
prev = 1 ; current = 1 . next ; 
cp = current .proc; 
while (cp != p) { 
prev = current ; 
current = current . next ; 
cp = current . proc ; 
} 

// remove 'current 1 and ' p 1 from active list 
nxt = current . next ; 
prev . next = nxt ; current . 
current. proc = null; 
setRole (current : IsolatedCell) ; 
// remove 'p 1 from running list 
lp = p. prev; In = p. next; 



p. prev = null; p. next = null; 
lp.next = In; In. prev = lp; 
setRole(p : DeadProc); 



5.2 Operational Semantics 

In this section we give the operational semantics for our lan- 
guage. We focus on the first three columns in Figures 6 and 
7; the safety conditions in the fourth column are detailed in 
Section 5.4. 

Figure 6 gives the small-step operational semantics for 
the basic statements. We use A l+J B to denote the union 
A(J B where the sets A and B are disjoint. The program 
state consists of the stack s and the concrete heap H c . The 
stack s is a sequence of pairs p@proq G x (Proc x A/"), where 
p £ iVcFG(proc) is a program point, and proq G Proc x J\f 
is an activation record of procedure proc. Program points 
p £ iVcFG(proc) are nodes of the control-flow graphs. There 
is one control-flow graph for every procedure proc. An edge 
of the control-flow graph {p,p'} G .EcFG(proc) indicates that 
control may transfer from point p to point p' . We write 
p : stat to state that program point p contains a statement 
stat. The control flow graph of each procedure contains spe- 
cial program points entry and exit indicating procedure en- 
try and exit, with no statements associated with them. We 
assume that all conditions are of the form x==y or ! (x==y) 
where x and y are either variables or a special constant null 
which always points to the null c object. 

The concrete heap is either an error heap error c or a non- 
error heap . A non-error heap H c C N x F x iVU ( ( P roc x Af) x 
V x N) is a directed graph with labelled edges, where nodes 
represent objects and procedure activation records, whereas 
edges represent heap references and local variables. An edge 
(oi,/, 02) G N x F x N denotes a reference from object 01 
to object 02 via field / G F. An edge (proq,x, o) G H c 
means that local variable x in activation record proq points 
to object o. 

A load statement x=y.f makes the variable x point to 
node Of, which is referenced by the f field of object o y , 
which is in turn referenced by variable y. A store statement 
x.f=y replaces the reference along field f in object o x by 
a reference to object o y that is referenced by y. The copy 
statement x=y copies a reference to object o v into variable 
x. The statement x=new creates a new object o„ with all 
fields initially referencing null c , and makes x point to o n . 
The statement test(c) allows execution to proceed only if 
condition c is satisfied. 

Figure 7 describes the semantics of procedure calls. Pro- 
cedure call pushes new activation record onto stack, inserts 
it into the heap, and initializes the parameters. Procedure 
entry initializes local variables. Procedure exit removes the 
activation record from the heap and the stack. 



5.3 Onstage and Offstage Objects 

At every program point the set of all objects of heap H c can 
be partitioned into: 



Statement 


Transition 


Constraints 


Role Consistency 


p : x=y . f 


<p@proq;s,-Hcl±l{<proq,x, 0ic )}) — > 
{p'QproCjja.fli) 


x, y G local(proc), 

{proq,y,Oj / ),{o 3; ,f,o / ) G He, 

<p,p') G ScFG(proc), 

H' c = H c l+J {proq,x,o/} 


accessible(o/, proc t ,H c ), 
con(^,offstage(^)) 


p : x.f=y 


{pQproq; s, i? c tt) {{ G:c , /, o/>}) ^ 
{p'Qproq;^} 


x, y G local(proc), 

{proc i ,x,o x ),{proq,y,o 3 ,} G He, 

{p,p') G ScFG(proc), 


Of G onstage(.ff c , proq) 
con(ff>ffstage(i^)) 


p : x=y 


{p@proq; s,.ff c l±l {{proq, x, o*)}) — > 
<p'@proq; S ,i^> 


x G local(proc), 

y G var(proc), 

<proq,y,Oj,) G H c , 

{p,p) G -Ecfg(pi-oc), 

H' c =H C l±l{{proc i; x,Oj,)} 


con(^,ofFstage(^)) 


p : x=new 


{p@proq;s,ff c l±l{{proq ; x ;0ic )}) — > 
<p'@proc,; S ,^) 


x G local(proc), 

o n fresh, 

{p,p') G -EJcfg(pi-oc), 

H' c = H c l+J {{proq,x, o„)} 1+) nulls, 

nulls = {o„} x F x {null} 


con(^,offstage(^)) 


p : test (c) 


(pQproc^s,^) — ► 
{p'Qproc^s,^} 


satisfied c (c, proq, i? c ), 
<p,p'} G F CFG (proc) 


co n ( H c , offsta ge ( H c ) ) 



satisfied c (x==y, proq, H c ) iff {o | {proq,x, o) G H c } = {o | {proc^y, o) G i? c } 
satisfied c ( ! (x==y) , proq, i? c ) iff not satisfied c (x==y, proc i; H c ) 

accessible(o, proc i ,H c ) := (3p G param(proc) : (proc i; p,o) G H c ) 

or not (BproCj- 3v G var(proc') : {proc'j,v,o) G H c ) 

Figure 6: Semantics of Basic Statements 



Statement 


Transition 


Constraints 


Role Consistency 


entry : _ 


<p@proq; a, H c ) — y 
{p'Qproq; s,H c 1+) nulls) 


nulls = {{proc^t;, nullc) | 
v G local(proc), 
(P,P') e FcFG(proc) 


con(iy c ,offstage(i? c )) 


p : prod(x k )k 


<p@proq; a, H c ) — y 
(entryQproc^p'Qproq; s,H' c ) 


,;' fresh in p@prod; a, 

(p,p') GFcFG(proc), 

Ok ■ {proc i; Xfc,Ofc) G H c , 

H' c = H c \S{(prodj,pk,Ok)}k, 

VA; Pk = param A ,(proc') 


conW(ra,-Hc,S), 
ra = {{oj fe ,preR jfe (proc'))} l fe, 
5 = offstage(i? c )U{o*}* 


exit : _ 


<p@proq; a,H c ) — y 
{s,H c \AF) 


AF = {<proq,t;,n) | 
<proq,u,7z) G H c } 


conW(ra,i? c ,5), 
ra = {{parnd fe (proc i ),postR yfe (proc))} fc , 
5 = offstage(.ff c ) U 

{o | {proc u v,o) G H c } 



parnd jfe (proc i ) = o where {proq, param A ,(proc),o) G H c 



Figure 7: Semantics of Procedure Call 



1. onstage objects (onstage(-ff c )) referenced by a local 
variable or parameter of some activation frame; 



onstage(.ff c , proq): 
onstage(.ff c ): 



= {o | 3x G var(proc) 

(proq,a;,o) G H c ) 
-- |J onstage(i? c ,proCj) 



proc; 



2. offstage objects (offstage(-ffc)) unreferenced by local 
or parameter variables. 

offstage(-ffc) := nodes(-ffc) \ onstage(if c ) 



Onstage objects need not have correct roles. Offstage objects 
must have correct roles assuming some role assignment for 
onstage objects. 

Definition 18 Given a set of role definitions and a set of 
objects S c C nodes(Sc), we say that heap H c is role con- 
sistent for S c , and we write con(H c ,S c ), iff there exists a 
role assignment p c : nodes(H c ) — > Ro such that the predi- 
cate locallyConsistent(o, H c ,p c , S c ) is satisfied for every ob- 
ject o G S c - 

We define locallyConsistent(o, H c ,p c , S c ) to generalize the 
locallyConsistent(o, H c ,p c ) predicate, weakening the acyclic- 
ity condition. 

Definition 19 locallyConsistent(o, H c ,p c , S c ) holds iff con- 
ditions 1), 2), and 3) of Definition 2 are satisfied and the 
following condition holds: 

4 ') It is not the case that graph H c contains a cycle 
o\,fi, . . . ,o s , f s ,oi such that 
oi=o,/i,...,/, £ acyclic(r), and 
additionally o\ , . . . , o s £S C . 

Here S c is the set of onstage objects that are not allowed 
to create a cycle; objects in nodes(H c ) \ S c are exempt from 
the acyclicity condition. The locallyConsistent(o, H c ,p c , S c ) 
and con (H c , S c ) predicates are monotonic in S c , so a larger 
S c implies a stronger invariant. For S c = nodes(-ffc), consis- 
tency for S c is equivalent with heap consistency from Defini- 
tion 1. Note that the role assignment p c specifies roles even 
for objects o G nodes(-ffc) \ S c - This is because the role of 
o may influence the role consistency of objects in S c which 
are adjacent to o. 

At procedure calls, the role declarations for parameters 
restrict the set of potential role assignments. We therefore 
generalize con(H c , S c ) to conW(ra,.ffc, S c ), which restricts 
the set of role assignments p c considered for heap consis- 
tency. 

Definition 20 Given a set of role definitions, a heap H c , a 
set S c C nodes(.ff c ), and a partial role assignment ra C S c — > 
R, we say that the heap H c is consistent with ra for S c , and 
write conW(ra, H c , S c ), iff there exists a (total) role assign- 
ment p c ■ nodes(.ff c ) — > Ro such that ra C p c and for every 
object o G S c the predicate locallyConsistent(o, H c ,p c , S c ) is 
satisfied. 



5.4 Role Consistency 

We are now able to precisely state the role consistency re- 
quirements that must be satisfied for program execution. 
The role consistency requirements are in the fourth row of 
Figures 6 and 7. We assume the operational semantics is 
extended with transitions leading to a program state with 
heap error c whenever role consistency is violated. 

5.4.1 Offstage Consistency 

At every program point, we require con(.ff c ,offstage(.ffc)) to 
be satisfied. This means that offstage objects have correct 
roles, but onstage objects may have their role temporarily 
violated. 



5.4.2 Reference Removal Consistency 

The Store statement x.f=y has the following safety precon- 
dition. When a reference {o x ,f, o/) G H c for {proCj,x, o x ) G 
H c , and (o x ,f,o/) G H c is removed from the heap, both o x 
and Of must be referenced from the current procedure ac- 
tivation record. It is sufficient to verify this condition for 
Of, as o x is already onstage by definition. The reference re- 
moval consistency condition enables the completion of the 
role change for o/ after the reference {o x ,f,Of} is removed 
and ensures that heap references are introduced and removed 
only between onstage objects. 

5.4.3 Procedure Call Consistency 

Our programming model ensures role consistency across pro- 
cedure calls using the following protocol. 

A procedure call prod (xi,...,x p ) in Figure 7 requires the 
role consistency precondition conW(ra,i? c ,5 c ), where the 
partial role assignment ra requires objects Ok , corresponding 
to parameters Xk, to have roles preR fc (proc') expected by the 
callee, and S c = offstage(if c )U{ofc}fc for {proc^a^Ojfe) G H c . 

To ensure that the callee proc^ never observes incorrect 
roles, we impose an accessibility condition for the callee's 
Load statements (see the fourth column of Figure 6). The 
accessibility condition prohibits access to any object o ref- 
erenced by some local variable of a stack frame other than 
proCj, unless o is referenced by some parameter of proc^. 
Provided that this condition is not violated, the callee proc^ 
only accesses objects with correct roles, even though objects 
that it does not access may have incorrect roles. In Section 7 
we show how the role analysis ensures that the accessibility 
condition is never violated. 

At the procedure exit point (Figure 7), we require cor- 
rect roles for all objects referenced by the current activation 
frame proc^. This implies that heap operations performed 
by proc' preserve heap consistency for all objects accessed 
by proCj. 

5.4.4 Explicit Role Check 

The programmer can specify a stronger invariant at any pro- 
gram point using statement roleCheck(a;i, . . . ,x p , ra). As 
Figure 8 indicates, roleCheck requires the conW(ra, H c , S c ) 
predicate to be satisfied for the supplied partial role assign- 
ment ra where S c = offstage(i? c ) U {ok}k for objects ou ref- 
erenced by given local variables Xk- 



Statement 


Transition 


Constraints 


Role Consistency 


p : roleCheck(a;i, . . . ,x n , ra) 


(pOproq; s,H c ) — > 
<p'@proq;s,if c ) 


{p,p') £ E CK 


conW(ra,if c ,S), 
5 = offstage(.ff c ) U 

{o | {proc t , x k ,o) eH c ) 



Figure 8: Operational Semantics of Explicit Role Check 



5.5 Instrumented Semantics 

We expect the programmer to have a specific role assignment 
in mind when writing the program, with this role assignment 
changing as the statements of the program change the ref- 
erencing relationships. So when the programmer wishes to 
change the role of an object, he or she writes a program that 
brings the object onstage, changes its referencing relation- 
ships so that it plays a new role, then puts it offstage in its 
new role. The roles of other objects do not change. 2 

To support these programmer expectations, we introduce 
an augmented programming model in which the role assign- 
ment p c is conceptually part of the program's state. The 
role assignment changes only if the programmer changes it 
explicitly using the setRole statement. The augmented pro- 
gramming model has an underlying instrumented semantics 
as opposed to the original semantics. 

Example 21 The original semantics allows asserting differ- 
ent roles at different program points even if the structure of 
the heap was not changed, as in the following procedure f oo. 

role Al { fields f : Bl; } 
role Bl { slots Al.f; } 
role A2 { fields f : B2; } 
role B2 { slots A2.f; } 
procedure foo() 
var x, y; 
{ 

x = new; y = new; 

x.f = y; 

roleCheck(x,y, x:Al,y:Bl); 

roleCheck(x,y, x:A2,y:B2); 



setRole(x:A2); setRole(y :B2) ; 
roleCheck(x,y, x:A2,y:B2); 
} 

The setRole statement makes the role change of object ex- 
plicit. 

The instrumented semantics extends the concrete heap 
H c with a role assignment p c . Figure 9 outlines the changes 
in instrumented semantics with respect to the original se- 
mantics. We introduce a new statement setRole (x : r) , 
which modifies a role assignment p c , giving p c [o x >-* r], 
where o x is the object referenced by x. All statements 
other than setRole preserve the current role assignment. 
For every consistency condition conW(ra, H c , S c ) in the orig- 
inal semantics, the instrumented semantics uses the cor- 
responding condition conW(p c U ra, H C ,S C ) and fails if p c 
is not an extension of ra. Here we consider con(H c ,S) 
to be a shorthand for conW(0, H c , S). For example, the 
new role consistency condition for the Copy statement 
x=y is conW(/9 c , H c ,offstage(H c )). The New statement as- 
signs an identifier unknown to the newly created object o n . 
By definition, a node with unknown does not satisfy the 
locallyConsistent predicate. This means that setRole must 
be used to set a a valid role of o n before o n moves offstage. 

By introducing an instrumented semantics we are not sug- 
gesting an implementation that explicitly stores roles of ob- 
jects at run-time. We instead use the instrumented seman- 
tics as the basis of our role analysis and ensure that all role 
checks can be statically removed. Because the instrumented 
semantics is more restrictive than the original semantics, our 
role analysis is a conservative approximation of both the in- 
strumented semantics and the original semantics. 



Both role checks would succeed since each of the spec- 
ified partial role assignments can be extended to a 
valid role assignment. On the other hand, the check 
roleCheck(x,y, x:Al,y:B2) would fail. 

The procedure f oo in the instrumented semantics can be 
written as folllows. 

procedure foo() 

var x, y; 

{ 

x = new; y = new; 

x.f = y; 

setRole (x : Al) ; setRole(y:Bl) ; 

roleCheck(x,y, x:Al,y:Bl); 



2 An extension to the programming model supports cas- 
cading role changes in which a single role change propagates 
through the heap changing the roles of offstage objects, see 
Section 8.2. 



6 Intraprocedural Role Analysis 

This section presents an intraprocedural role analysis algo- 
rithm. The goal of the role analysis is to statically verify 
the role consistency requirements described in the previous 
section. 

The key observation behind our analysis algorithm is that 
we can incrementally verify role consistency of the concrete 
heap H c by ensuring role consistency for every node when it 
goes offstage. This allows us to represent the statically un- 
bounded offstage portion of the heap using summary nodes 
with "may" references. In contrast, we use a "must" in- 
terpretation for references from and to onstage nodes. The 
exact representation of onstage nodes allows the analysis to 
verify role consistency in the presence of temporary viola- 
tions of role constraints. 

Our analysis representation is a graph in which nodes rep- 
resent objects and edges represent references between ob- 
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Statement 


Transition 


Constraints 


Role Consistency 


p : x=new 


(pQproq; a, H c l±l {(proq, x, o x )}, p c ) — > 
{p' ©proc-, s,H' c ,p' c ) 


x G local(proc), 

o n fresh, 

(p,p') eEcK(proc), 

H c = H c 

l±J{(proq,x,o„)} 

l±l{o„} x Fx {null}, 

Pc = pc[o n <-y unknown] 


conW(^,^,offstage(^)) 


V ■ 
setRole(x:r) 


{p@proq;s,i? c ,/9 c ) — > 
{p' ©proc-, s,H c ,p' c ) 


x G local(proq), 
(proc^x^) eH c , 

p'c = Pc[o x i-^r], 
<p,p') e -BcFG 


conW(p^,if c ,offstage(iy c )) 


p : Stat 


(s,H c ,p c ) — y 
{s',H' c ,p c ) 


{a,H c )^{a',H' c ) 


PAconW(p c Ura,if^',5) 

for every original condition 

PAcon\N(ra,H'J,S) 



Figure 9: Instrumented Semantics 



jects. There are two kinds of nodes: onstage nodes repre- 
sent onstage objects, with each onstage node representing 
one onstage object; and offstage nodes, with each offstage 
node corresponding to a set of objects that play that role. 
To increase the precision of the analysis, the algorithm oc- 
casionally generates multiple offstage nodes that represent 
disjoint sets of objects playing the same role. Distinct off- 
stage objects with the same role r represent disjoint sets of 
objects of role r with different reachability properties from 
onstage nodes. 

We frame role analysis as a data-flow analysis operating 
on a distributive lattice 'P(RoleGraphs) of sets of role graphs 
with set union U as the join operator. In this section we 
present an algorithm for intraprocedural analysis. We use 
proc c to denote the topmost activation record in a concrete 
heap H c . In Section 7 we generalize the algorithm to the 
compositional interprocedural analysis. 

6.1 Abstraction Relation 

Every data-flow fact Q C RoleGraphs is a set of role graphs 
G G Q- Every role graph G G RoleGraphs is either a bot- 
tom role graph J_g representing the set of all concrete heaps 
(including error c ), or a tuple G = {H, p, K) representing non- 
error concrete heaps, where 

• HCNxFxN is the abstract heap with nodes N 
representing objects and fields F. The abstract heap 
H represents heap references (rii , /, 712) and variables of 
the currently analyzed procedure (proc, x, n) where x G 
local(proc). Null references are represented as references 
to abstract node null. We define abstract onstage nodes 
onstage(-ff) = {n | (proc, x,n) G -ff, x G local(proc) U 
param(proc)} and abstract offstage nodes offstage(-ff) = 
nodes(-ff) \ onstage(-ff) \ {proc, null}. 

• p : nodes(if) — y Ro is an abstract role assignment, 
p(null) = nulljj; 

• K : nodes(-ff) — y {«, a) indicates the kind of each node; 
when K{n) = i, then n is an individual node repre- 
senting at most one object, and when K(n) = s, n is a 
summary node representing zero or more objects. We 



require -ftT(proc) = iiT(null) = i, and require all onstage 
nodes to be individual, -ftT[onstage(.ff)] = {i}. 

The abstraction relation a relates a pair {H c ,p c ) of con- 
crete heap and concrete role assignment with an abstract 
role graph G. 



Definition 22 We say that an abstract role graph G rep- 
resents concrete heap H c with role assignment p c and write 
{H c ,p c )aG, iffG = ± G or: H c £ error c , G = {H,p,K), 
and there exists a function h : nodes(H c ) — y nodes(-ff) such 
that 

1) H c is role consistent: conW(/9 c ,i? c , offstage(if c )), 

2) identity relations of onstage nodes with offstage nodes 
hold: if (oi,/,02) G H c and (02,3,03) G H c for 01 G 
onstage(-ffc), 02 G offstage (H c ), and 

(/, g) G identities(p c (oi)), then 03 = 01; 

3) h is a graph homomorphism: if (01,/, 02) G H c then 
(h( 0l ),f,h(02))eH; 

4) an individual node represents at most one concrete ob- 
ject: K{n) = i implies |ft _1 (n)| < 1; 

5) h is bisection on edges which originate or terminate at 
onstage nodes: if (roi, /, 712) G H and n\ G onstage(if) 
or 712 G onstage(-ff), then there exists exactly one 

(01, /, 02) G H c such that h{o\) = n\ and h{o2) = n^; 

6) ft(null c ) = null and ft(proc c ) = proc; 

7) the abstract role assignment p corresponds to the con- 
crete role assignment: p c (o) = p(h(o)) for every object 
o G nodes(-ffc)- 

Note that the error heap error c can be represented only by 
the bottom role graph J_g- The analysis uses J_g to indicate 
a potential role error. 

Condition 3) implies that role graph edges are a conserva- 
tive approximation of concrete heap references. These edges 
are in general "may" edges. Hence it is possible for an off- 
stage node n that (n, /, ni), (n, /, 712) G H for m ^ 712- This 
cannot happen when n G onstage(-ff) because of 5). Another 
consequence of 5) is that an edge in H from an onstage node 
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(Hc>Pc)- 




Figure 10: Abstraction Relation 



no to a summary node n s implies that n s represents at least 
one object. Condition 2) strengthens 1) by requiring certain 
identity constraints for onstage nodes to hold, as explained 
in Section 6.2.4. 



Example 23 Consider the following role declaration for an 
acyclic list. 

role L { // List header 

fields first : LN | null; 
} 
role LN { // List node 

fields next : LN | null; 

slots LN.next | L. first; 

acyclic next; 
} 

Figure 10 shows a role graph and one of the concrete heaps 
represented by the role graph via homomorphism h. There 
are two local variables, prev and current, referencing dis- 
tinct onstage objects. Onstage objects are isomorphic to 
onstage nodes in the role graph. In contrast, there are two 
objects mapped to each of the summary nodes with role LN 
(shown as LN-labelled rectangles in Figure 10). Note that the 
sets of objects mapped to these two summary nodes are dis- 
joint. The first summary LN-node represents objects stored 
in the list before the object referenced by prev. The second 
summary LN-node represents objects stored in the list after 
the object referenced by current. 




Gi 1 



-(H' c ,p'c) 



G 3 




y g a 



Figure 11: Simulation Relation Between Abstract and Con- 
crete Execution 



6.2 Transfer Functions 

The key complication in developing the transfer functions 
for the role analysis is to accurately model the movement 
of objects onstage and offstage. For example, a load state- 
ment x=y.f may cause the object referred to by y.f to move 
onstage. In addition, if x was the only reference to an on- 
stage object o before the statement executed, object o moves 
offstage after the execution of the load statement, and thus 
must satisfy the locallyConsistent predicate. 

The analysis uses an expansion relation -< to model the 
movement of objects onstage and a contraction relation y 
to model the movement of objects offstage. The expansion 
relation uses the invariant that offstage nodes have correct 
roles to generate possible aliasing relationships for the node 
being pulled onstage. The contraction relation establishes 
the role invariants for the node going offstage, allowing the 
node to be merged into the other offstage nodes and repre- 
sented more compactly. 

We present our role analysis as an abstract execution re- 
st 
lation "-». The abstract execution ensures that the abstrac- 
tion relation a is a forward simulation relation [33] from 
the space of concrete heaps with role assignments to the set 
RoleGraphs. The simulation relation implies that the traces 
of ~» include the traces of the instrumented semantics — >. 
To ensure that the program does not violate constraints as- 
sociated with roles, it is thus sufficient to guarantee that J_g 
is not reachable via ~-». 

To prove that _I_g is not reachable in the abstract execu- 
tion, the analysis computes for every program point p a set 
of role graphs Q that conservatively approximates the pos- 
sible program states at point p. The transfer function for a 

statement st is an image [st](<5) = {G' \ G 6 



g,g%g'}. 



The analysis computes the relation ~» in three steps: 

1. ensure that the relevant nodes are instantiated using 
expansion relation ■< (Section 6.2.1); 



2. perform symbolic execution 
(Section 6.2.3); 



of the statement st 



3. merge nodes if needed using contraction relation y to 
keep the role graph bounded (Section 6.2.2). 

Figure 11 shows how the abstraction relation a relates ■<, 
st 
=£•, and y with the concrete execution — > in instrumented 

semantics. Assume that a concrete heap {H c ,p c } is repre- 
sented by the role graph Gi . Then one of the role graphs G2 
obtained after expansion remains an abstraction of {H c ,p c }. 
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Transition 


Definition 


Conditions 


{H,p,K) v ^ 1 G' 


n yJ x=V.f n x 

(H,p,K) < Gi =L> G2>G' 


{proc, x, n x ),{proc, y, n y ) G ff 


{H,p,K) X ^G' 


x=v n l 

(H,p,K)=i.Gi>:G' 


{proc, x, ni) G ff 


(H,p,K) x= ^ v G' 


(H,p,K)'^G 1 hG' 


{proc, x, ni) G ff 


{H,p,K)^G' 


{ff,p,K)=^G' 


s G {x.f=y, 

test (c) , 

setRole(x:r) , 

roleCheck(xi.. p , ra)} 



Figure 12: Abstract Execution 



St 



The symbolic execution => followed by the contraction rela- 
tion >; corresponds to the instrumented operational seman- 
tics — >. 

Figure 12 shows rules for the abstract execution relation 

. Only Load statement uses the expansion relation, be- 
cause the other statements operate on objects that are al- 
ready onstage. Load, Copy, and New statements may re- 
move a local variable reference from an object, so they use 
contraction relation to move the object offstage if needed. 
For the rest of the statements, the abstract execution re- 
duces to symbolic execution => described in Section 6.2.3. 

St 

Nondeterminism and Failure The ^~> relation is not a 
function because the expansion relation -< can generate a set 
of role graphs from a single role graph. Also, there might be 

St 

no ~» transitions originating from a given state G if the sym- 
bolic execution => produces no results. This corresponds 
to a trace which cannot be extended further due to a test 
statement which fails in state G. This is in contrast to a 
transition from G to J_g which indicates a potential role con- 
sistency violation or a null pointer dereference. We assume 
that =$■ and > relations contain the transition {_I_g,J-g) 
to propagate the error role graph. In most cases we do not 
write the explicit transitions to error states. 



6.2.1 Expansion 



»,/ 



Figure 13 shows the expansion relation < . Given a role 
graph {ff , p, K) expansion attempts to produce a set of role 
graphs {ff' , p' ,K') in each of which {n, /, no) G ff' and 
K{no) = i. Expansion is used in abstract execution of the 
Load statement. It first checks for null pointer dereference 
and reports an error if the check fails. If {n, /, n') G ff and 
K(n') = i already hold, the expansion returns the original 
state. Otherwise, {n,f,n') G ff with K(n') = s. In that 
case, the summary node n' is first instantiated using instan- 

uq no 

tiation relation -ff- Next, the split relation || is applied. Let 

n 1 

p(«o) = r. The split relation ensures that no is not a member 
of any cycle of offstage nodes which contains only edges in 
acyclic(r). We explain instantiation and split in more detail 
below. 

Instantiation Figure 14 presents the instantiation rela- 

n 

tion. Given a role graph G = (H,p,K), instantiation -ff 



generates the set of role graphs {ff' , p' ,K') such that each 
concrete heap represented by {.ff, p, K) is represented by one 
of the graphs {ff' ,p' ,K'}. Each of the new role graphs con- 
tains a fresh individual node no that satisfies localCheck. 
The edges of no are a subset of edges from and to n' . 

Let ffo be a subset of the references between n' and on- 
stage nodes, and let ffi be a subset of the references between 
n' and offstage nodes. References in ff are moved from n' 
to the new node no, because they represent at most one ref- 
erence, while references in ffi are copied to no because they 
may represent multiple concrete heap references. Moving a 
reference is formalized via the swing operation in Figure 14. 

The instantiation of a single graph can generate multiple 
role graphs depending on the choice of ff and ffi . The num- 
ber of graphs generated is limited by the existing references 
of node n' and by the localCheck requirement for no- This is 
where our role analysis takes advantage of constraints asso- 
ciated with role definitions to reduce the number of aliasing 
possibilities that need to be considered. 

Split The split relation is important for verifying opera- 
tions on data structures such as skip lists and sparse matri- 
ces. It is also useful for improving the precision of the initial 
set of role graphs on procedure entry (Section 7.2.1). 

The goal of the split relation is to exploit the acyclicity 
constraints associated with role definitions. After a node no 
is brought onstage, split represents the acyclicity condition 
of p(no) explicitly by eliminating impossible paths in the 
role graph. It uses additional offstage nodes to encode the 
reachability information implied by the acyclicity conditions. 
This information can then be used even after the role of node 
no changes. In particular, it allows the acyclicity condition 
of no to be verified when no moves offstage. 

Example 24 Consider a role graph for an acyclic list with 
nodes LN and a header node L. The instantiated node no is 
in the middle of the list. Figure 16 a) shows a role graph 
with a single summary node representing all offstage LN- 
nodes. Figure 16 b) shows the role graph after applying 
the split relation. The resulting role graph contains two 
LN summary nodes. The first LN summary node represents 
objects definitely reachable from no along next edges; the 
second summary NL node represents objects definitely not 
reachable from no- 

Figure 15 shows the definition of the split operation on 

n 

node no, denoted by || . Let G = {H,p,K) be the initial 
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Transition 


Definition 


Condition 


(H,p,K) <{H,p,K) 




{n, /, n') G ff, n' G onstage(if) 


{ff.p.JO jG' 


n n 

{H,p,K)^{H uPu K{) || G' 

n' 


{n, /,n'} £ H,ri £ offstage(if) 
(n, /, n ) G Hi 



Figure 13: Expansion Relation 



H' =H\H \JH' \JH[ 

p' = p[n i-y p(n')] 

K' = K[n >->■ i] 

\oca\Check(n , (H',p',K')) 

H CHr\ (onstage(i?) x F x {ri} U {n'} x F x onstage(if)) 

Hi CHH (offstage(-ff) x F x {n'} U {n'} x F x offstage(-ff)) 

i/ = swing(n',no,-ffo) 

ifj C swing(n',no,-ffi) 



n 

{H,p,K)-fr{H',p',K') 

n> 



swing(n | d ,nnew,ii") = 



{{nnew, /, n) \ {n M , /, n) G H} U 
{<n, /, nnew) | (n, /, n Q | d ) G -ffj U 
{{nnew,/, nnew) | <n | d , /,n | d ) G H} 



Figure 14: Instantiation Relation 



{H,p,K) \\{H,p,K), acycCheck(n , {H,p,K), ofFstage(-ff)) 

no 

(H,p,K) \\(H',p',K'), ^acycCheck(n ,{H,p,K),offstage{H)) 



where 



H = (H\ H cyc ) U -ffoff U -BfNR U Bm U BtNR U B m U iV f U N t 

-ffcyc = {{ni, /, n 2 ) | ni or n 2 G 5 cyc } 

H s = {{ni,/, n' 2 ) | ni =c(ni),n 2 = c(n' 2 ), 

ni,n 2 G offstage^-ff)^! or n 2 G 5 cy c, 

{m,/,n 2 )Gff} 
\(Sr x acyclic(r) x 5nr) 
H n (onstage(.H") xFU {no} x acyclic(r)) x 5 cyc = ^4fNR ttl ^4fR 
H n Scyc x (acyclic(r) x {no} 1) F x onstage(.H")) = ^4 t NR W -A t R 
-BfNR = {{ni,/, ftNR(n 2 )) | {ni,/, n 2 ) G -AfNit} 
-Bm = {{ni , /, ft R (n 2 )) | {ni , /, n 2 ) G ^4m} 
B tN R = {(/iNR(ni),/, n 2 ) | <ni,/, n 2 ) G Anr} 
-B t R = {{ft R (ni),/,n 2 ) | (ni,/,n 2 ) G 4ir} 
iV f = {{no, /, n') | n' G Sr, {n , /, c(n')) G H , / G acyclic(r)} 
^t = {{n',/,n ) | n' G 5nr, (c(n'), /,n ) £ H, f £ acyclic(r)} 
Scyc = {" I 3ni, . . . , n p _i G offstage(.ff) : 

(n ,/o,ni),. ■■,{n k ,fk,n),{n,fk+i,n k +2),{ n P-iifp-ii n o) £ H , 
/o,- --,/p-i G acyclic(r)} 
offstage! (H) = offstage(.ff) \ {n } 
r = p{no) 

p'(c(n)) =p{n) 
K'(c(n)) = K(n) 



Figure 15: Split Relation 
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b) After Split 



Figure 16: A Role Graph for an Acyclic List 



role graph and p(no) = r. If acyclic(r) = 0, then the split 
operation returns the original graph G; otherwise it proceeds 
as follows. Call a path in graph H cycle-inducing if all of its 
nodes are offstage and all of its edges are in acyclic(r). Let 
Scyc be the set of nodes n such that there is a cycle-inducing 
path from no to n and a cycle-inducing path from re to no- 
The goal of the split operation is to split the set S cyc into 
a fresh set of nodes Snr representing objects definitely not 
reachable from no along edges in acyclic(r) and a fresh set of 
nodes Sr representing objects definitely reachable from no- 
Each of the newly generated graphs H' has the following 
properties: 

1) merging the corresponding nodes from Snr and Sr in 
H' yields the original graph H; 

2) no is not a member of any cycle in H 1 consisting of 
offstage nodes and edges in acyclic(r); 

3) onstage nodes in H 1 have the same number of fields and 
aliases as in H. 

Let So = nodes(-ff) \S cyc and let /inr : S cyc — > Snr and hn : 
Sc y c — ► Sr be bijections. Define a function c : nodes(-ff') — > 
nodes(-ff) as follows: 



c(n) 



n, 

ft NR("). 



n G So 
n G Sr 

n G Snr 



Then H' C {{n' u f,n' 2 ) | <c(ni), /,c(n' 2 )) G H}. 

Because there are two copies of So in H 1 , there might be 
multiple edges {n'i,f, n' 2 ) in H' corresponding to an edge 
{c(i»i),/,c(n 2 )>eff. 



If both n'i and n' 2 are offstage nodes other than no, we 
always include {ni,/, n' 2 ) in H' unless {ni,/, n 2 ) G Sr x 
acyclic(r) x Snr- The last restriction prevents cycles in H 1 . 
For an edge {ni,/, n 2 ) G H where n\ G onstage(-ff) and 
«2 G Scyc we include in H 1 either the edge {m, /, foiR(n 2 )) 
or {m, /, /»R(n 2 )) but not both. Split generates multiple 
graphs H' to cover both cases. We proceed analogously if 
n 2 G onstage(-ff) andni G S cyc . The node no itself is treated 
in the same way as onstage nodes for / ^ acyclic(r). If 
/ G acyclic(r) then we choose references to no to have a 
source in Snr, whereas the reference from no have the target 
in Sr. 

Details of the split construction are given in Figure 15. 
The intuitive meaning of the sets of edges is the following: 
H Q s : edges between offstage nodes 
-BfNR : edges from onstage nodes to Snr 
.BfR : edges from onstage nodes to Sr 
-BtNR : edges from Snr to onstage nodes 
-B t R : edges from Sr to onstage nodes 
Ni : acyclic(r)-edges from no to Sr 
N t : acyclic(r)-edges from Snr to no 
The sets BfNR and BfR are created as images of the sets 
^IfNR and ^4fR which partition edges from onstage nodes to 
nodes in S C y C - Similarly, the sets B tN R and B tR are created 
as images of the sets ^Unr and ^4 t R which partition edges 
from nodes in S cy c to onstage nodes. 

We note that if in the split operation S cyc = then the 
operation has no effect and need not be performed. In Fig- 
ure 16, after performing a single split, there is no need to 
split for subsequent elements of the list. Examples like this 
indicate that split will not be invoked frequently during the 
analysis. 



6.2.2 Contraction 

Figure 17 shows the non-error transitions of the contraction 

n 

relation y. The analysis uses contraction when a reference 
to node n is removed. If there are other references to n, 
the result is the original graph. Otherwise n has just gone 
offstage, so analysis invokes nodeCheck. If the check fails, 
the result is _1_g- If the role check succeeds, the contrac- 
tion invokes normalization operation to ensure that the role 
graph remains bounded. For simplicity, we use normaliza- 
tion whenever nodeCheck succeeds, although it is sufficient 
to perform normalization only at program points adjacent 
to back edges of the control-flow graph. 

Normalization Figure 18 shows the normalization rela- 
tion. Normalization accepts a role graph {H, p, K) and pro- 
duces a normalized role graph {H 1 ,p' ,K') which is a factor 
graph of {H,p,K) under the equivalence relation ~. Two 
offstage nodes are equivalent under ~ if they have the same 
role and the same reachability from onstage nodes. Here we 
consider node n to be reachable from an onstage node no 
iff there is some path from no to n whose edges belong to 
acyclic(/9(no)) and whose nodes are all in offstage(-ff). Note 
that, by construction, normalization avoids merging nodes 
which were previously generated in the split operation ||, 
while still ensuring a bound on the size of the role graph. 
For a procedure with / local variables, / fields and r roles the 
number of nodes in a role graph is on the order of r2 l so the 
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n 


3x G var(proc) : 
{proc, x, n) G H 


n 

{H, p,K) ^normalize({.H", p, K)) 


nodeCheck(n, (H, p, K), offstage(-ff)) 



Figure 17: Contraction Relation 



norma lize«.H",p, if)) = (H,p,K') 






where H 1 = {{m/~, /, t»2/~) | {m,/, r^) G #} 
p'(n/~) =p(«) 

n/~ = {«}, -f (n) = » 
otherwise 
n\ ~ «2 iff «i = «2 or 

(ni,n 2 G affstage(H),p(m) = p{n 2 ), 
Vno G onstage(-ff) : (reach(no, m) iff reach(n , W2)) 
reach(no,n) iff 3ni, . . . , n p _i £ offstage(n), 3/i, . . . , f p G acyclic(p(no)) 
{no,/i,ni),...,{n p -i,/ p ,n) G ff 



Figure 18: Normalization 



maximum size of a chain in the lattice is of the order of 2 r2 . 
To ensure termination we consider role graphs equal up to 
isomorphism. Isomorphism checking can be done efficiently 
if normalization assigns canonical names to the equivalence 
classes it creates. 

6.2.3 Symbolic Execution 

St 

Figure 19 shows the symbolic execution relation =>. In 
most cases, the symbolic execution of a statement acts on 
the abstract heap in the same way that the statement would 
act on the concrete heap. In particular, the Store statement 
always performs strong updates. The simplicity of symbolic 
execution is due to conditions 3) and 5) in the abstraction 
relation a. These conditions are ensured by the ■< relation 
which instantiates nodes, allowing strong updates. The sym- 
bolic execution also verifies the consistency conditions that 
are not verified by ■< or y. 



Verifying Reference Removal Consistency 

St 



The ab- 



stract execution ~» for the Store statement can easily verify 
the Store safety condition from section 5.4.2, because the 
set of onstage and offstage nodes is known precisely for ev- 
ery role graph. It returns J_g if the safety condition fails. 

Symbolic Execution of setRole The setRole(x:r) 
statement sets the role of node n x referenced by variable 
x to r. Let G = {H, p, K) be the current role graph and 
let {proc, x, n x ) G H. If n x has no adjacent offstage nodes, 
the role change always succeeds. In general, there are re- 
strictions on when the change can be done. Let {H c , p c ) 
be a concrete heap with role assignment represented by G 
and ftbea homomorphism from H c to H. Let h(o x ) = n x . 
Let ro = p c (o x )- The symbolic execution must make sure 
that the condition conW(/9 c , H c ,offstage(H c )) continues to 
hold after the role change. Because the set of onstage nodes 
does not change, it suffices to ensure that the original roles 



for offstage nodes are consistent with the new role r. The 
acyclicity constraint involves only offstage nodes, so it re- 
mains satisfied. The other role constraints are local, so they 
can only be violated for offstage neighbors of n x . To make 
sure that no violations occur, we require: 

1. r G field/(p(n)) for all {n, /, n x ) G -ff, and 

2. {r, /) G slot,(p(n)) for all {n x , /, n) G H and every slot 
i such that {ro, /) G slot,(p(n)) 

This is sufficient to guarantee conW(/9 c , i7 c ,offstage(if c )). 
To ensure condition 2) in Definition 22 of the abstraction 
relation, we require that for every {/, g) G identities(r), 



1- {/, p) G identities(ro) or 

2. for all (n x ,f,n) G H: K(n) 
implies n' = n x ). 



and ({n, g, n') G H 



Symbolic Execution of roleCheck To symbolically ex- 
ecute roleCheck(a;i, . . . ,a; p , ra), we ensure that the conW 
predicate of the concrete semantics is satisfied for the con- 
crete heaps which correspond to the current abstract role 
graph. The symbolic execution for roleCheck returns the 
error graph J_g if p is inconsistent with ra or if any of the 
nodes rn referenced by Xi fail to satisfy nodeCheck. 

6.2.4 Node Check 

The analysis uses the nodeCheck predicate to incrementally 
maintain the abstraction relation. We first define the pred- 
icate localCheck, which roughly corresponds to the predi- 
cate loca NyConsistent (Definition 2), but ignores the nonlo- 
cal acyclicity condition and additionally ensures condition 
2) from Definition 22. 



Definition 25 For a role graph G = {H,p,K), an 

ual node n and a set S, the predicate localCheck(n, G) holds 
iff the following conditions are met. Let r = p(n). 
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Statement s 


Transition 


Conditions 


x = y.f 


{H l±l {proc, x, n x }, p, K) =^> {H l±l {proc, x, n/}, p, K) 


{proc,y,n v ),{n„,/,n/) G ff 


x.f = y 


{H\S{n x J,n f },p,K)^{H\t){n x J,n y },p,K) 


{proc, x, n x ), {proc, y, n v ) G if 
n/ G onstage(-ff) 


x = y 


{H\£ {proc,x,n x },p, K) =^> {H l±l {proc,x,n„},/9,.fir) 


{proc,y,n„} G -ff 


x = new 


{i?l±l {proc, x,n x },p, K)=^{H\±) {proc,x,n„},p', K) 


n„ fresh 
p' = p[n n i-t unknown] 


test(c) 


{H,p,K)^{H,p,K) 


satisfied (c, H) 


setRole(x:r) 


{H,p,K)^{H,p[n x ^r],K) 


{proc, x, n x ) G H 
ro\eChOk(n x ,r,{H,p,K)) 


roleCheck(a;i..p, ra) 


(H,p,K)^{H,p,K) 


Vi {proc, x,,n,) G i? 

nodeCheck(ni, {.ff, p, K), S) 

S = offstage(-ff) U {n*}, 

/g(rij) = ra(n,) 



satisfied (x==y, H c ) iff {o | {proc, x, o) G H c } = {o | {proc, y, o) G H c } 
satisfied ( ! (x==y) , H c ) iff not satisfied (x==y, H c ) 

Figure 19: Symbolic Execution of Basic Statements 



1A. (Outgoing fields check) For fields f G F, if{n,f,n'} G 
H then p(n') G field/(r). 

2A. (Incoming slots check) Let {{ni, /i), ••-,{«*, /*)} = 
{{n',/} | {n',f,n) G H} be the set of all aliases of 
node n in abstract heap H. Then k = slotno(r) and 
there exists a permutation p of the set {1, . . . ,k} such 
that {p(rii), fi) G slot Pi (r) for all i. 

3A. (Identity Check) If{n,f,n') G H, {n',g,n") G H, 
if id) ^ identities(r), and K(n') = i, then n = n" . 

4 A. (Neighbor Identity Check) For every edge {n , /, n) G H , 
if K(n') = i, p(n') = r' and {f,g) G identities(r') then 
{n,g,ri} G H. 

5 A. (Field Sanity Check) For every f G F there is exactly 
one edge {n,f,n') G H. 

Conditions 1A and 2A correspond to conditions 1) and 2) 
in Definition 2. Condition 3) in Definition 19 is not neces- 
sarily implied by condition 3A) if some of the neighbors of 
n are summary nodes. Condition 3) cannot be established 
based only on summary nodes, because verifying an identity 
constraint for field / of node n where {n, /, n') G H requires 
knowing the identity of n' , not only its existence and role. 
We therefore rely on Condition 2) of the Definition 22 to 
ensure that identity relations of neighbors of node n are sat- 
isfied before n moves offstage. 

The predicate acycCheck(n, G, S) verifies the acyclicity 
condition from Definition 19. 

Definition 26 We say that node n satisfies an acyclicity 
check in graph G = (H,p,K) with respect to set S, and we 
write acycCheck(n, G, S), iff it is not the case that H con- 
tains a cycle n\ , f\ , . . . , n s , f s , n\ where n\ = n, /i , . . . , /» G 
acyclic(/9(n)) and m, . . . ,n s G S. 

This enables us to define the nodeCheck predicate. 

Definition 27 nodeCheck(n, G, S) holds iff both predicates 
localCheck(n, G) and acycCheck(n, G, 5) hold. 



7 Interprocedural Role Analysis 

This section describes the interprocedural aspects of our role 
analysis. Interprocedural role analysis can be viewed as an 
instance of the functional approach to interprocedural data- 
flow analysis [41]. For each program point p, role analysis 
approximates program traces from procedure entry to point 
p. The solution in [41] proposes tagging the entire data-flow 
fact G at point p with the data flow fact Go at procedure en- 
try. In contrast, our analysis computes the correspondence 
between heaps at procedure entry and heaps at point p at 
the granularity of sets of objects that constitute role graphs. 
This allows our analysis to detect which regions of the heap 
have been modified. We approximate the concrete execu- 
tions of a procedure with procedure transfer relations con- 
sisting of 1) an initial context and 2) a set of effects. Effects 
are fine-grained transfer relations which summarize load and 
store statements and can naturally describe local heap mod- 
ifications. In this paper we assume that procedure transfer 
relations are supplied and we are concerned with a) verifying 
that transfer relations are a conservative approximation of 
procedure implementation b) instantiating transfer relations 
at call sites. 



7.1 Procedure Transfer Relations 

A transfer relation for a procedure proc extends the pro- 
cedure signature with an initial context context(proc), and 
procedure effects effect(proc). 



7.1.1 Initial Context 

Figures 20 and 21 contain examples of initial context speci- 
fication. An initial context is a description of the initial role 
graph {H K ,pic,K K } where p lc and K lc are determined by a 
nodes declaration and H lc is determined by a edges declara- 
tion. The initial role graph specifies a set of concrete heaps 
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at procedure entry and assigns names for sets of nodes in 
these heaps. The next definition is similar to Definition 22. 

Definition 28 We say that a concrete heap (H c ,p c ) is rep- 
resented by the initial role graph (H K ,p K ,K K ) and write 
{H c ,p c )ao{H K ,p\c,K K ), iff there exists a function ho : 
nodes(.ff c ) — > nodes(-ffic) such that 

1. con\N(p c ,H c ,hQ 1 (read(proc)); 

2. ho is a graph homomorphism; 

3. K K (n) = i implies \h^ 1 (n)\ < 1; 

4- fto(nullc) = null and fto(proc c ) = proc; 

5. pc(o) = p\c(ho(o)) for every object o G nodes(if c ). 

Here read (proc) is the set of initial-context nodes read by 
the procedure (see below). For simplicity, we assume one 
context per procedure; it is straightforward to generalize the 
treatment to multiple contexts. 

A context is specified by declaring a list of nodes and a 
list of edges. 

A list of nodes is given with nodes declaration. It specifies 
a role for every node at procedure entry. Individual nodes 
are denoted with lowercase identifiers, summary nodes with 
uppercase identifiers. By using summary nodes it is possible 
to indicate disjointness of entire heap regions and reachabil- 
ity between nodes in the heap. 

There are two kinds of edges in the initial role graph: pa- 
rameter edges and heap edges. A parameter edge p->pn is 
interpreted as (proc, p, pn) G H K . We require every parame- 
ter edge to have an individual node as a target, we call such 
node a parameter node. The role of a parameter node refer- 
enced by pararrij(proc) is always preR^proc). Since different 
nodes in the initial role graph denote disjoint sets of concrete 
objects, parameter edges 

pi -> nl 
p2 -> nl 

imply that parameters pi and p2 must be aliased, 

pi -> nl 
p2 -> n2 

force pi and p2 to be unaliased, whereas 

pi -> nl|n2 
p2 -> nl|n2 

allow for both possibilities. A heap edge n -f-> m denotes 
(n, f,m) G -Hie- The shorthand notation 

nl -f-> n2 
-g-> n3 

denotes two heap edges (nl,f ,n2), (nl,g, n3) G H lc . An ex- 
pression nl -f-> n2|n3 denotes two edges nl -f-> n2 and 
nl -f-> n3. We use similar shorthands for parameter edges. 

Example 29 Figure 20 shows an initial context graph for 
the kill procedure from Example 17. It is a refinement of 
the role reference diagram of Figure 1 as it gives description 
of the heap specific to the entry of kill procedure. The 
initial context makes explicit the fact that there is only one 
header node for the list of running processes (ph) and one 




nodes ph : RunningHeader, 

PI, px, P2 : RunningProc, 
lx : LiveHeader, 
LL1, 12, LL2 : LiveList; 
edges p-> px, l-> px, 
ph -next-> Pl|px 

-prev-> px|P2, 
PI -next-> Pllpx 

-prev-> ph|Pl, 
px -next-> P2|ph 

-prev-> Pl|ph, 
P2 -next-> P2|ph 

-prev-> P2|px, 
lx -next-> LL1|12, 
LL1 -next-> LL1|12 

-proc-> Pl|P2|SleepingProc 
12 -next-> LL2|null 

-proc-> px, 
LL2 -next-> LL2|null 

-proc-> Pl|P2|SleepingProc 



Figure 20: Initial Context for kill Procedure 



header node for the list of all active processes (lx). More im- 
portantly, it shows that traversing the list of active processes 
reaches a node 12 whose proc field references the parameter 
node px. This is sufficient for the analysis to conclude that 
there will be no null pointer dereferences in the while loop 
of kill procedure since 12 is reached before null. 



We assume that the initial context always contains the role 
reference diagram RRD (Definition 8). Nodes from RRD are 
called anonymous nodes and are referred to via role name. 
This further reduces the size of initial context specifications 
by leveraging global role definitions. In Figure 20 there is 
no need to specify edges originating from SleepingProc or 
even mention the node SleepingTree, since role definitions 
alone contain enough information on this part of the heap 
to enable the analysis of the procedure. 
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procedure insert (1 : L, 

x : IsolatedN -» LN) 
nodes In, xn; 
edges l-> In, x-> xn, 

In -next-> LN|null; 
effects ln|LN . next = xn, 

! xn.next = LN|null; 
local c, p; 
{ 

p = i; 

c = 1 . next ; 
while (c!=null) { 
p = c; 
c = p . next ; 
} 

p. next = x; 
x.next = c; 
setRole(x:LN) ; 
} 

Figure 21: Insert Procedure for Acyclic List 



7.1.2 Procedure Effects 

Procedure effects conservatively approximate the region of 
the heap that the procedure accesses and indicate changes 
to the referencing relationships in that region. There are two 
kinds of effects: read effects and write effects. 

A read effect specifies a set read(proc) of initial graph 
nodes accessed by the procedure. It is used to ensure that 
the accessibility condition in Section 5.4.3 is satisfied. If the 
set of nodes denoted by read(proc) is mapped to a node n 
which is onstage in the caller but is not an argument of the 
procedure call, a role check error is reported at the call site. 

Write effects are used to modify caller's role graph to con- 
servatively model the procedure call. A write effect e\.j = C2 
approximates Store operations within a procedure. The ex- 
pression ei denotes objects being written to, / denotes the 
field written, and C2 denotes the set of objects which could 
be assigned to the field. Write effects are may effects by de- 
fault, which means that the procedure is free not to perform 
them. It is possible to specify that a write effect must be 
performed by prefixing it with a " ! " sign. 

Example 30 In Figure 21, the insert procedure inserts 
an isolated cell into the end of an acyclic singly linked list. 
As a result, the role of the cell changes to LN. The initial 
context declares parameter nodes In and xn (whose initial 
roles are deduced from roles of parameters), and mentions 
anonymous LN node from a default copy of the role reference 
diagram RRD. The code of the procedure is summarized 
with two write effects. The first write effect indicates that 
the procedure may perform zero or more Store operations 
to field next of nodes mapped to In or LN in context(proc). 
The second write effect indicates that the execution of the 
procedure must perform a Store to the field next of xn node 
where the reference stored is either a node mapped onto 
anonymous LN node or null. 

Effects also describe assignments that procedures perform 
on the newly created nodes. Here we adopt a simple solution 
of using a single summary node denoted N EW to represent 



procedure insertSome(l : L) 
nodes In; 
edges l-> In, 

In -next-> LN|null; 
effects ln|LN . next = NEW, 
NEW. next = LN|null; 
aux c , p , x ; 
{ 

p = i; 

c = 1 . next ; 
while (c!=null) { 

p = c; 

c = p . next ; 
} 

x = new; 
p. next = x; 
x . next = c ; 
setRole(x:LN) ; 



Figure 22: Insert Procedure with Object Allocation 



all nodes created inside the procedure. We write nodeso(-ffic) 
for the set nodes(-ff lc ) U {NEW}. 

Example 31 Procedure insertSome in Figure 22 is similar 
to procedure insert in Figure 21, except that the node in- 
serted is created inside the procedure. It is therefore referred 
to in effects via generic summary node NEW. 

We represent all may write effects as a set mayWr(proc) of 
triples {nj,f,n'j) where n,n'j G nodeso(-ffic) and / G F. We 
represent must write effects as a sequence mustWrj(proc) of 
subsets of the set K' 1 ^) x F x nodeso(-ffic). Here 1 < j < 
mustWrNo(proc). 

To simplify the interpretation of the declared proce- 
dure effects in terms of concrete reads and writes, we re- 
quire the union UimustWr,(proc) to be disjoint from the 
set mayWr(proc). We also require the nodes m,...,n% in 
a must write effect n\ \ ■ ■ ■ \nk-f = e-i to be individual nodes. 
This allows strong updates when instantiating effects (Sec- 
tion 7.3.2). 

7.1.3 Semantics of Procedure Effects 

We now give precise meaning to procedure effects. Our def- 
inition is slightly complicated by the desire to capture the 
set of nodes that are actually read in an execution while still 
allowing a certain amount of observational equivalence for 
write effects. 

The effects of procedure proc define a subset of per- 
missible program traces in the following way. Consider 
a concrete heap H c with role assignment p c such that 
{H c , p c ) ao{H lc , pic, K K ) with graph homomorphism ho from 
Definition 28. Consider a trace T starting from a state with 
heap H c and role assignment p c . Extract the subsequence 
of all loads and stores in trace T. Replace Load x=y.f by 
concrete read read o x where o x is the concrete object refer- 
enced by x at the point of Load, and replace Store x.f=y by 
a concrete write o x .f = o y where o x is the object referenced 
by x and o v object referenced by y at the point of Store. Let 
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pi, . . . ,Pk be the sequence of all concrete read statements 
and qi, ■ ■ ■ ,qk the sequence of all concrete write statements. 
We say that trace T starting at H c conforms to the effects 
iff for all choices of ho the following conditions hold: 

1. ho(o) G read(proc) for every p, of the form read o 

2. there exists a subsequence qt 1 , ■ ■ ■ , qt t of q\ , . . . , qk such 
that 

(a) executing q^ , . . . , qt t on H c yields the same result 
as executing the entire sequence qi , . . . , qk 

(b) the sequence qi 1 , . . . , qi t implements write effects 
of procedure proc 



the analysis to perform must effect folding by recording only 
the last must effect for every pair (n, /) of individual node 
n and field /. 



. , qi t from the se- 



A typical way to obtain a sequence qi x , . 

quence qi, ■ ■ ■ ,qk is to consider only the last write for each 

pair {oi, f) of object and field. 

We say that a sequence qi 1 , . . . , qi t implements write ef- 
fects mayWr(proc) and mustWr,(proc) for 1 < i < i , 
io = mustWrNo if and only if there exists an injection 
s : {1, . . . , io} — ► {ii , • • • , it} such that 

1. (ft'(o), /, ft'(o')) G mustWr,(proc) for every concrete 
write q s (i} of the form o.f = o' , and 

2. (ft'(o), /, h'(o')) G mayWr(proc) for all concrete writes 
qi of the form o.f = o' for i G {»i,...,»t} \ 

{8(l),...,8(io)}. 

Here h! (n) = ho(n) for n G nodes(i? c ) where H c is the initial 
concrete heap and ft'(n) = NEW otherwise. 

It is possible (although not very common) for a single 
concrete heap H c to have multiple homomorphisms ho to 
the initial context H c . Note that in this case we require the 
trace T to conform to effects for all possible valid choices 
of ho- This places the burden of multiple choices of ho on 
procedure transfer relation verification (Section 7.2) but in 
turn allows the context matching algorithm in Section 7.3.1 
to select an arbitrary homomorphism between a caller's role 
graph and an initial context. 

7.2 Verifying Procedure Transfer Relations 

In this section we show how the analysis makes sure that a 
procedure conforms to its specification, expressed as an ini- 
tial context with a list of effects. To verify procedure effects, 
we extend the analysis representation from Section 6.1. A 
non-error role graph is now a tuple {H , p, K, t, E) where: 

1. t : nodes(-ff) — > nodeso(-ffic) is initial context trans- 
formation that assigns an initial context node r(n) G 
nodes(-ffic) to every node n representing objects that 
existed prior to the procedure call, and assigns NEW to 
every node representing objects created during proce- 
dure activation; 

2. E C UimustWr,(proc) is a list of must write effects that 
procedure has performed so far. 

The initial context transformation r tracks how objects have 
moved since the beginning of procedure activation and is 
essential for verifying procedure effects which refer to initial 
context nodes. 

We represent the list E of performed must effects as a par- 
tial map from the set K^{i) x F to nodeso(-ffic). This allows 



[entry.] = {{H,p,K,r,E) 

P : {proc} x {pararrij(proc)} 



N, P C H K 

Ho = (H K \ {proc} x param(proc) x N) U P 
rii = P(proc, paramj(proc)) 
H ! C H o 

Hi\H C {{!»', /.n") | {ni,n 2 }n{ni}i / 0} 
V; : localCheck(nj, (if, p, K), nodes(-ffi)) 

n\ n2 n p 

Hi || Hi || • • • || H 

P = Pic 
K = K K 

T = p,c 

E 



= 0} 



Figure 23: The Set of Role Graphs at Procedure Entry 



7.2.1 Role Graphs at Procedure Entry 

Our role analysis creates the set of role graphs at proce- 
dure entry point from the initial context context(proc). This 
is simple because role graphs and the initial context have 
similar abstraction relations (Sections 6.1 and 7.1). The dif- 
ference is that parameters in role graphs point to exactly one 
node, and parameter nodes are onstage nodes in role graphs 
which means that all their edges are "must" edges. 

Figure 23 shows the construction of the initial set of role 
graphs. First the graph H is created such that every pa- 
rameter pararrij(proc) references exactly one parameter node 
rii. Next graph Hi is created by using localCheck to ensure 
that parameter nodes have the appropriate number of edges. 
Finally, the instantiation is performed on parameter nodes 
to ensure acyclicity constraints if the initial context does not 
make them explicit already. 

7.2.2 Verifying Basic Statements 

To ensure that a procedure conforms to its transfer relation 
the analysis uses the initial context transformation t to as- 
sign every Load and Store statement to a declared effect. 
Figure 24 shows new symbolic execution of Load, Store and 
New statements. 

The symbolic execution of Load statement x=y.f makes 
sure that the node being loaded is recorded in some read 
effect. If this is not the case, an error is reported. 

The symbolic execution of the Store statement x. f =y first 
retrieves nodes r(n x ) and r(n y ) in the initial role graph 
context that correspond to nodes n x and n v in the current 
role graph. If the effect {r(n x ), /, T(n y )} is declared as a may 
write effect the execution proceeds as usual. Otherwise, the 
effect is used to update the list E of must- write effects. The 
list E is checked at the end of procedure execution. 

The symbolic execution of the New statement updates the 
initial context transformation t assigning r(n„) = NEW for 
the new node n„. 
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Statement s 


Transition 


Constraints 


x = y.f 


{H\tj {proc, x, n x },p,K, r,E)=>{H\tJ {proc,x,n/},p, K, t, E) 


{proc,y,n„),{n v ,/,n/} G H 
T~(rif) G read(proc) 


x = y.f 


{H l±J {proc, x, n x }, p, K, t, E) =l> J_g 


{proc,y,n3,),{n v ,/,n/} G H 
r(n/) ^ read(proc) 


x.f = y 


(Hkl{n x ,f,n f },p,K,T,E)^{Hkl{n x ,f,n y },p,K,T,E) 


{proc, x,^}, {proc, y,n y ) G ff 
{T~(n x ),f,T(n y )} G mayWr(proc) 


x.f = y 


{HV{n x J,n f },p,K,T,E)=^{H\S{n x J,n y },p,K,T,E') 


{proc, x,nx), {proc, y,n„) G -ff 
{r(n x ),f,T(n y )) G UmustWri(proc) 
£' = updateWr(£;, ( T (n x ), /, r(n v )}) 


x.f = y 


{HV{n x J,n f },p,K,T,E)=^± G 


{proc, x, n x ), {proc, y,n y ) e H 

{ T ( n x),f,T(n y )) g mayWr(proc)U 

UjmustWr,(proc) 


x = new 


(H l+J {proc, x, n x }, p, K, t, E) =l> (H l+J {proc, x, n„},p, K, r' \E) 


n„ fresh 
t' =T[n„i-)-NEVV] 



updateWr(.E, {m,/,n 2 )) = £[{«!,/) >->■ n 2 ] 



Figure 24: Verifying Load, Store, and New Statements 



The t transformation is similarly updated during other 
abstract heap operations. Instantiation of node n into node 
no assigns r(no) = i"(n'), split copies values of t into the new 
set of isomorphic nodes, and normalization does not merge 
nodes n\ and n 2 if t{ji\) =£ t{ti2)- 

7.2.3 Verifying Procedure Postconditions 

At the end of the procedure, the analysis verifies that p{n{) = 
postRj(proc) where {proc, param^proc),^) G -ff, and then 
performs node check on all onstage nodes using predicate 
nodeCheck(n, {if, p, -ftT), nodes(-ff)) for all n G onstage(-ff). 

At the end of the procedure, the analysis also verifies 
that every performed effect in E = {ei, . . . ,e*} can be at- 
tributed to exactly one declared must effect. This means 
that k = mustWrNo(proc) and there exists a permutation s 
of set {l,...,k} such that e s ^ G mustWr,(proc) for all i. 

7.3 Analyzing Call Sites 

The set of role graphs at the procedure call site is up- 
dated based on the procedure transfer relation as follows. 
Consider procedure proc containing call site p G iV C FG(proc) 
with procedure call proc'(zi,. . . ,z p ). Let {-ffic,/9ic,-£Gc) = 
context(proc') be the initial context of the callee. 

Figure 25 shows the transfer function for procedure call 
sites. It has the following phases: 

1. Parameter Check ensures that roles of parameters 
conform to the roles expected by the callee proc' . 

2. Context Matching (matchContext) ensures that the 
caller's role graphs represent a subset of concrete heaps 
represented by context(proc'). This is done by deriving 
a mapping u from the caller's role graph to nodes(-ffic). 

3. Effect Instantiation ( — >) uses effects mayWr(proc') 
and mustWr;(proc') in order to approximate all struc- 
tural changes to the role graph that proc' may perform. 



[proc'(zi,...,z p )](e) = 

if 3G G Q : -.paramCheck(G) then {_L G } 
else try Gi = matchContext(C?) 
if failed then {J_g} 
else{G"|{G,«)G6!i 

{addNEW(G), u) -^>{G', u) -^> G"} 

paramCheck({iJ, p, K, t, E)) iff 

Vn, : nodeCheck(n,, G, offstage(-ff) U {«*}») 
rii are such that {proc, Xi,rii) G H 

addNE\N((H,p,K,T,E)) = 

{H U{n } x F x {null}, 

p[no i-» unknown], 

K[n i-» s], 

r[n i-» NEW], 

E) 
where no is fresh in H 



Figure 25: Procedure Call 



4. Role Reconstruction ( — >) uses final roles for param- 
eter nodes and global role declarations postR^proc') to 
reconstruct roles of all nodes in the part of the role 
graph representing modified region of the heap. 

The parameter check requires nodeCheck(n», G, offstage(if )U 
{rii}i) for the parameter nodes in. The other three phases 
are explained in more detail below. 

7.3.1 Context Matching 

Figure 26 shows our context matching function. The 
matchContext function takes a set Q of role graphs and pro- 
duces a set of pairs {G, p) where G = {H, p, K, t, E) is a role 
graph and u is a homomorphism from H to H lc . The homo- 
morphism p guarantees that a~ 1 (G) C a ~ 1 (context(proc')) 
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matchContext(6) = match({<G, nodes(G) x {±}) | G G Q}) 
match : 7>(RoleGraphs x (N U {-L})^) -* 7>(RoleGraphs x N N ) 
match(r) = 

ro:={<G,p)er|p- 1 (±)/0}; 

if To = then return V; 

{{H,p,K,r,E),p) := choose T ; 

r' = T\{{H,p,K,T,E),p); 

paramnodes := {n | 3» : (proc,a;i,n) G ff}; 

inaccessible := onstage(-ff) \ paramnodes; 

no := choose u _1 (_L); 

candidates := {n' G nodes(-ffic) | 

(no ^ inaccessible and pic(n') = p(no)) or 
(no G inaccessible and n' ^ read(proc'))} 

fl {n'|{n',/,«(n))Gffic} 

(n J,n)eH 

fl {n'|{Mn),/,n')e^ic}; 

(n,f,n )eH 

if candidates = then fail ; 

if candidates = {n },-ftT(no) = s,-ftTic(n ) 



,p- 1 (n o ) = 



then match(r'U {<G',p[m M- n ]) | {H,p,K,r,E) i\ G'}) 

else n := choose {n' G candidates | K(n') = s or 

( J ff(n o ) = i,p- 1 (n') = 0)} 
match(r' U «.H", p, K, t, E), p[n M- n' ]}); 



Figure 26: The Context Matching Algorithm 



since the homomorphism ho from Definition 28 can be con- 
structed from homomorphism h in Definition 22 by putting 
ho = /j, o h. This implies that it is legal to call proc' with any 
concrete graph represented by G. 

The algorithm in Figure 26 starts with empty maps p = 
nodes(G) x {_L} and extends u until it is defined on all 
nodes(G) or there is no way to extend it further. It pro- 
ceeds by choosing a role graph {H, p, K, t, E) and node no 
for which the mapping jj, is not defined yet. It then finds 
candidates in the initial context that no can be mapped to. 
The candidates are chosen to make sure that p remains a 
homomorphism. The accessibility requirement — that a pro- 
cedure may see no nodes with incorrect role — is enforced 
by making sure that nodes in inaccessible are never mapped 
into nodes in read for the callee. As long as this requirement 
holds, nodes in inaccessible can be mapped onto nodes of any 
role since their role need not be correct anyway. We gener- 
ally require that the set /i _1 (n ) for individual node n in 
the initial context contain at most one node, and this node 
must be individual. In contrast, there might be many indi- 
vidual and summary nodes mapped onto a summary node. 
We relax this requirement by performing instantiation of a 
summary node of the caller if, at some point, that is the only 
way to extend the mapping jj, (this corresponds to the first 
recursive call in the definition of match in Figure 26). 

The algorithm is nondeterministic in the order in which 
nodes to be matched are selected. One possible ordering 



of nodes is depth-first order in the role graph starting from 
parameter nodes. If some nondeterministic branch does not 
succeed, the algorithm backtracks. The function fails if all 
branches fail. In that case the procedure call is considered 
illegal and J_g is returned. The algorithm terminates since 
every procedure call lexicographically increases the sorted 
list of numbers |p[nodes(iif)]| for {{H,p,K,T,E),jj,) G T. 

7.3.2 Effect Instantiation 

The result of the matching algorithm is a set of pairs (G, p) 
of role graphs and mappings. These pairs are used to instan- 
tiate procedure effects in each of the role graphs of the caller. 
Figure 30 gives rules for effect instantiation. The analysis 
first verifies that the region read by the callee is included in 
the region read by the caller. Then it uses map p to find 
the inverse image S of the performed effects. The effects in 
S are grouped by the source n and field /. Each field n.f 
is applied in sequence. There are three cases when applying 
an effect to n.f: 

1. There is only one node target of the write in nodes(-ff) 
and the effect is a must write effect. In this case we do 
a strong update. 

2. The condition in 1) is not satisfied, and the node n is 
offstage. In this case we conservatively add all relevant 
edges from S to H. 
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3. The condition in 1) is not satisfied, but the node n is 
onstage i.e. it is a parameter node 3 . In this case there 
is no unique target for n.f, and we cannot add multi- 
ple edges either as this would violate the invariant for 
onstage nodes. We therefore do case analysis choosing 
which effect was performed last. If there are no must ef- 
fects that affect n, then we also consider the case where 
the original graph is unchanged. 

7.3.3 Role Reconstruction 

Procedure effects approximate structural changes to the 
heap, but do not provide information about role changes 
for non-parameter nodes. We use the role reconstruction 

algorithm — > in Figure 27 to conservatively infer possible 
roles of nodes after the procedure call based on role changes 
for parameters and global role definitions. 

Role reconstruction first finds the set N of all nodes that 
might be accessed by the callee since these nodes might have 
their roles changed. Then it splits each node n G N into \R\ 
different nodes p(n,r), one for each role r G R. The node 
p(n, r) represents the subset of objects that were initially 
represented by n and have role r after procedure executes. 
The edges between nodes in the new graph are derived by 
simultaneously satisfying 1) structural constraints between 
nodes of the original graph; and 2) global role constraints 
from the role reference diagram. The nodes p(n, r) not con- 
nected to the parameter nodes are garbage collected in the 
role graph. In practice, we generate nodes p(n, r) and edges 
on demand starting from parameters making sure that they 
are reachable and satisfy both kinds of constraints. 



8 Extensions 

This section presents two extensions of the basic role system. 
The first extension allows statically unbounded number of 
aliases for objects. The second extension allows the analysis 
to verify more complex role changes. Additional ways of 
extending roles are given in [31]. 

8.1 Multistats 

A multislot {r', /) G multislots(r) in the definition of role r 
allows any number of aliases {o',f,o} G H c for p c {o') = r' 
and p c {o) = r. We require multislots multislots(r) to be 
disjoint from all sloti(r). To handle multislots in role analysis 
we relax the condition 5) in Definition 22 of the abstraction 
relation by allowing h to map more than one concrete edge 
{o', /, o) onto abstract edge {n , /, n) G H terminating at an 
onstage node n provided that {p{n'),f} G multislots(p(n)). 
The nodeCheck and expansion relation ■< are then extended 
appropriately. Note that a role graph does not represent 
the exact number of references that fill each multislot. The 
analysis therefore does not attempt to recognize actions that 
remove the last reference from the multislot. Once an object 
plays a role with a multislot, all subsequent roles that it plays 
must also have the multislot. 



3 Non-parameter onstage nodes are never affected by ef- 
fects, as guaranteed by the matching algorithm. 



role BufferNode { 

fields next : BufferNode | null; 

slots Buff erNode . next | main. buffer; 

acyclic next; 
} 
role WorkNode { 

fields next : WorkNode | null; 

WorkNode . next | main. work; 

acyclic next; 
} 

procedure main() 

rootvar buffer : BufferNode | null , 

work : WorkNode | null; 
auxvar x, y; 
{ 

// create buffer and work lists 

// swap buffer and work 

x = buffer; 

y = work; 

buffer = y; 

work = x; 

setRoleCascade(x: WorkNode, y:Buff erNode) ; 



Figure 28: Example of a Cascading Role Change 



8.2 Cascading Role Changes 

In some cases it is desirable to change roles of an entire set of 
offstage objects without bringing them onstage. We use the 
statement setRoleCascade (xi : n,...,x n '■ r n ) to perform 
such cascading role change of a set of nodes. The need for 
cascading role changes arises when roles encode reachability 
properties. 

Example 32 Procedure main in Figure 28 has two root 
variables, buffer and work, each being a root for a 
singly linked acyclic list. Elements of the first list have 
BufferNode role and elements of the second list have 
WorkNode role. At some point procedure swaps the root 
variables buffer and work, which requires all nodes in both 
lists to change the roles. These role changes are triggered 
by the setRoleCascade statement. The statement indicates 
new roles for onstage nodes, and the analysis cascades role 
changes to offstage nodes. 

Given a role graph {H, p, K, E) cascading role change finds 
a new valid role assignment p' where the onstage nodes 
have desired roles and the roles of offstage nodes are ad- 
justed appropriately. Figure 29 shows abstract execution 
of the setRoleCascade statement. Here neighbors(n, H) 
denotes nodes in H adjacent to n. The condition 
cascadingOk(n, H, p, K, p') makes sure it is legal to change 
the role of node n from p(n) to p' (n) given that the neigh- 
bors of n also change role according to p' . This check resem- 
bles the check for setRole statement in Section 6.2.3. Let 
r = rho(n) and r' = p'(n). Then cascadingOk(n, H, p, K, p') 
requires the following conditions: 

1. {n, /, ni) G H implies p'(«i) G field/(r') 
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{{H,p,K,T,E),ri-^{H',p',K',T',E') 

{proc,Xi,m) G H 

No = p _1 [read(proc')] 

s : No x R — ► N where s(n, r) are all different nodes fresh in H 

p' =p\(N xf?)U{<s(n,r),r) \neN ,reR} 
\({m}i xR)U {{m, postRi(proc))} 

K'(a(n,r)) = K(n) 

r'(s(n,r)) = t(ti) 

E' = E 

Ho = H\{(n u f,n 2 ) | ni G A^o or n 2 G N } 

U{{s(n 1 ,r 1 )J,s(n 2 ,r 2 )) \ (n u f,n 2 ) G H,{ ri J,r 2 ) G RRD} 
U{<m,/, S (n 2 ,r 2 )> | {mj,n 2 ) G H,{p K {p{ ni ))J,r 2 ) G RRD} 
U{{«(ni,ri),/,nj) | {n u f,n 2 ) G H,{r u f,p lc (p(n 2 ))) G RRD} 

H 1 = GC{H ) 



Figure 27: Call Site Role Reconstruction 



{H,p,K,T,E)^{H,p',K,r,E) 

s = setRoleCascade(a;i : r\, . . . ,x n ■ r n ) 



m : {proc, Xi,rii) G H 

p'{rii) = n 

p'(n) = p(n), n G onstage(if) \ {n,}. 

No = {n G offstage(.ff) | 3n' G neighbors(n, H) : p(ri) ± p'(n')} 

Vn G A^o : cascadingOk(n, H, p, K, p') 



Figure 29: Abstract Execution for setRoleCascade 



2. slotno(r') = slotno(r) = k, and for every list 
{ni, fi,n), . . . ,{nt, fk,n) G H if there is a permuta- 
tion p : {1, . . . , k} — > {1, . . . , k} such that {p(n,), fi) G 
slotp; (r), then there is a permutation p' : {1, . . . , k} — > 
{1, . . . , k} such that {p(rn), fi) G slot Pi (r'). 

3. identity relations were already satisfied or can be ex- 
plicitly checked: {/, g) G identities^' (n)) implies 

(a) {/, g) G identities(p(n)) or 

(b) for all <n, /,n'} G H: K(n') = i, and 
if (ri ,g,n") G H then n" = n 

4. either acyc\\c(p' (n)) C acyc\\c(p(n)) or 
acycCheck(n, {if, p',iir),offstage(ii")). 

In practice there may be zero or more solutions that satisfy 
constraints for a given cascading role change. Selecting any 
solution that satisfies the constraints is sound with respect 
to the original semantics. A useful heuristic for searching 
the solution space is to first explore branches with as few 
roles changed as possible. If no solutions are found, an error 
is reported. 

9 Related Work 

Typestate, as a type system extension for statically verifying 
dynamically changing properties, was proposed in [44, 43]. 
Aliasing causes problems for typestate-based systems be- 
cause the declared typestates of all aliases must change 
whenever the state of the referred object changes. Faced 
with the complexity of aliasing, [44] resorted to a more con- 
trolled language model which avoids aliasing. More recently 



proposed typestate approaches use linear types for heap ref- 
erences to support state changes of dynamic allocated ob- 
jects without addressing aliasing issues [10]. 

Motivated by the need to enforce safety properties in low- 
level software systems, [42, 46, 9] use extensions of linear 
types to describe aliasing of objects and rely on language 
design to avoid non-local type inference. These systems take 
a construction based approach that specifies data structures 
as unfoldings of basic elaboration steps [46]. Similarly to 
shape types [15, 14] and graph types [29, 34], this allows 
tree-like data structures to be expressed more precisely than 
using our roles, but cannot approximate data structures such 
as sparse matrices. More importantly, this approach makes 
it difficult to express nodes that are members of multiple 
data structures. Handling multiple data structures is the 
essential ingredient of our approach because the role of an 
object depends on data structures in which it participates. 

Like shape analysis techniques [5, 17, 39, 40] we have 
therefore adopted the constraint based approach which char- 
acterizes data structures in terms of the constraints that they 
satisfy. The constraint based approach allows us to handle a 
wider range of data structure while giving up some precision. 
Like [47, 48] we perform non-local inference of program prop- 
erties, but while [47, 48] focus on linear integer constraints 
and handle recursive data structures conservatively, we do 
not handle integer arithmetic but have a more precise rep- 
resentation of the heap. At a higher level, these approaches 
all focus on detailed properties of individual data structures. 
We view our research as focusing more on global aspects such 
as the participation of objects in multiple data structures. 

The path matrix approaches [18, 17] have been used to 
implement efficient interprocedural analyses that infer one 
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level of referencing relationships, but are not sufficiently pre- 
cise to track must aliases of heap objects for programs with 
destructive updates of more complex data structures. 

The use of the instantiation relation in role analysis is 
analogous to the materialization operation of [39, 40]. Role 
analysis can also track reachability properties, but we use an 
abstraction relation based on graph homomorphism rather 
than 3-valued logic. Our split operation achieves a similar 
goal to the focus operation of [40]. However, the generic 
focus algorithm of [32] cannot handle the reachability predi- 
cate which is needed for our split operation. This is because 
it conservatively refuses to focus on edges between two sum- 
mary nodes to avoid generating an infinite number of struc- 
tures. Rather than requiring definite values for reachability 
predicate, our role analysis splits by reachability properties 
in the abstract role graph, which illustrates the flexibility 
of the homomorphism-based abstraction relation. Another 
difference with [40] is that our role analysis does not require 
the developer to supply the predicate update formulae for 
instrumentation predicates. 

A precise interprocedural analysis [38] extends shape anal- 
ysis techniques to treat activation records as dynamically al- 
located structures. The approach also effectively synthesizes 
an application-specific set of contexts. Our approach differs 
in that it uses a less precise but more scalable treatment of 
procedures. It also uses a compositional approach that an- 
alyzes each procedure once to verify that it conforms to its 
specification. Like [48] our interprocedural analysis can ap- 
ply both may and must effects, but our contexts are general 
graphs with summary nodes and not trees. 

Roles are similar to the ADDS and ASAP data structure 
description languages [25, 26, 23]. These systems use sound 
techniques to apply the data structure invariants for paral- 
lelization and general dependence testing but do not verify 
that the data structure invariants are preserved by destruc- 
tive updates of data structures [24]. 

The object-oriented community has long been aware of 
benefits that dynamically changing classes give in large sys- 
tems [37]. Recognizing these benefits, researchers have pro- 
posed dynamic techniques that change the class of an object 
to reflect its state changes [16, 20, 4, 13]. These systems 
illustrate the need for a static system that can verify the 
correct use of objects with changing roles. 

10 Conclusion 

This paper proposes two key ideas: aliasing relationships 
should determine, in large part, the state of each object, 
and the type system should use the resulting object states 
as its fundamental abstraction for describing procedure in- 
terfaces and object referencing relationships. We present a 
role system that realizes these two key ideas in a concrete 
system, and present an analysis algorithm that can verify 
that the program correctly respects the constraints of this 
role system. The result is that programmers can use roles 
for a variety of purposes: to ensure the correctness of ex- 
tended procedure interfaces that take the roles of parameters 
into account, to verify important data structure consistency 
properties, to express how procedures move objects between 
data structures, and to check that the program correctly im- 
plements correlated relationships between the states of mul- 



tiple objects. We therefore expect roles to improve the re- 
liability of the program and its transparency to developers 
and maintainers. 
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